trivy (image)
Off-the-shelfTrivy again, pointed at the shipped container image rather than the source tree.
What it scans
The OCI image an artifact publishes, when it publishes one. Most packages ship no image, and for those this scanner is reported as not applicable rather than as a pass.
What it catches
- CVEs in the operating-system and language packages baked into the shipped image — the layers a source-tree scan never reads.
- Secrets and misconfiguration present in the image but absent from the repository.
Source and provenance
Nerlo pins and publishes each scanner's provenance so you can verify it yourself. Every scan surfaces the source, version, and install command in its report.
- Kind
- Off-the-shelf
- Source channel
- github releases (.deb)
- Pinned version
- 0.71.0
- License
- Apache-2.0
- Source URL
- https://github.com/aquasecurity/trivy