Built something? We create video reels & spotlights for GitHub projects.Promote your project →
aquasecurity
Home / Go / trivy

aquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go ◇ containers Apache-2.0
★38.2KSTARS
⑂721FORKS
!248ISSUES
🏆#334GLOBAL RANK
🔥5DAYS TRENDING
🚀
Maintainer Growth Kit for trivy

Claim this project, add your verified backlink badge to your README, and download milestone cards.

Claim Repo

Star History

Continuous Observations
Interactive star growth chart for aquasecurity/trivy
CSV
⭐ VIRAL README KIT

Add Live Star History & Verified Badges to README.md

Keep your repository README looking professional and dynamic. As our continuous crawler records new stars, these official SVG badges update in real time with zero maintenance.

Open README on GitHub ↗
Option 1: Interactive Star History Chart Dynamic SVG

Renders your high-resolution star trajectory chart right inside your GitHub README or project docs.

aquasecurity/trivy Star History Preview
markdown
[![Star History Chart](https://githubrepo.cloud/api/badge/chart/aquasecurity/trivy.svg?theme=dark)](https://githubrepo.cloud/repo/aquasecurity/trivy?utm_source=readme_chart)
Direct SVG Link ↗
Option 2: Verified Shields Badges Shields.io Style

Compact Shields-style badges for your README header. Shows real-time stars and global ranking.

Featured badge Stars badge Rank badge
markdown (badge trio)
[![Featured on GitHubRepo.cloud](https://githubrepo.cloud/badge/aquasecurity/trivy.svg?metric=featured)](https://githubrepo.cloud/repo/aquasecurity/trivy?utm_source=readme_badge) [![GitHubRepo Stars](https://githubrepo.cloud/badge/aquasecurity/trivy.svg?metric=stars)](https://githubrepo.cloud/repo/aquasecurity/trivy?utm_source=readme_badge) [![Global Rank](https://githubrepo.cloud/badge/aquasecurity/trivy.svg?metric=rank)](https://githubrepo.cloud/repo/aquasecurity/trivy?utm_source=readme_badge)

Momentum

+954

STARS · LAST 30 DAYS

32

PER DAY

#47

MOST-STARRED Go

Window7 days30 days90 days
Stars gained+224+954+2.9K
Per day323232
Forks gained+4+14+36

trivy gained 954 stars in the last 30 days, about 32 a day, and now has 38.2K. It is about 7 years old and has averaged roughly 5.5K stars a year. It ranks #47 among Go repositories and #334 across all languages on GitHubRepo.

Trending Record

trivy has maintained a continuous presence across global trending indexes, peaking at #2220. Below is the 30-day activity profile:

💡 Overview

trivy is an open-source project written in Go: Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more.

Engineered for speed, consistency, and developer ease, it solves common hurdles in containers, devsecops, docker. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.

⚡ Key Features

1

Optimized execution pipeline written in Go for predictable speed.

2

Zero-friction configuration with comprehensive sensible defaults out of the box.

3

Cross-platform runtime support across Linux, macOS, and Windows environments.

4

Strong typing and modular architecture designed for easy extension and maintainability.

5

Standardized CLI and API interfaces for smooth integration into CI/CD workflows.

6

Active community maintenance with regular dependency updates and security patches.

📥 Installation

terminal
$ go install github.com/aquasecurity/trivy@latest

⚙ System Requirements

Platforms

  • • macOS
  • • Linux
  • • Windows

Runtime & Dependencies

Go >= 1.21 runtime environment

Architecture

x86_64, ARM64 (Apple Silicon & Graviton)

🧠 How It Works

trivy coordinates its core functionality through a modular Go pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.

🎯 Production Use Cases

Autonomous AI Agents

Orchestrate intelligent workflows and tool-calling routines with trivy.

Model Inference & Prompting

Integrate fast, local or cloud-hosted generative AI models directly into production code.

Context Memory & RAG

Augment language models with dynamic vector retrieval and structured project memory.

Developer Productivity

Automate repetitive engineering tasks, code generation, and test creation using AI agents.

🚀 Getting Started

1

Install trivy using your package manager: `go install github.com/aquasecurity/trivy@latest`

2

Initialize your project workspace or configuration file for trivy.

3

Import trivy into your codebase or invoke it directly from your terminal.

4

Execute your test suite or run `trivy --help` to verify successful setup.

👍 Strengths

Active community backing with 38,167 GitHub stars and verified adoption.
Permissive open-source distribution under the Apache-2.0 license.
Built in Go for high execution speed and developer familiarity.
Cross-platform compatibility across modern Linux, macOS, and Windows environments.
Clean modular design allowing flexible configuration and pipeline integration.

⚠️ Considerations

Requires familiarity with Go and modern CLI workflows.
Ecosystem extensions may require manual configuration depending on environment constraints.
Active development roadmap means breaking API changes may occur across major versions.

⇄ Alternatives & Direct Competitors

A
avelino/awesome-go ★ 186.4K Go

A curated list of awesome Go frameworks, libraries and software

Compare ↗
O
ollama/ollama ★ 182.3K Go

Get up and running with Kimi, GLM, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models.

Compare ↗
G
golang/go ★ 139.1K Go

The Go programming language

Compare ↗
K
kubernetes/kubernetes ★ 128.2K Go

Production-Grade Container Scheduling and Management

Compare ↗

👥 Who Should Use This

Developers and engineering teams building with Go, seeking reliable, tested, and actively maintained tooling for production workloads.

🏆 Nearby in the Rankings

aquasecurity/trivy is currently ranked #334 by stars across every repository tracked on GitHubRepo. These are adjacent projects:

RankRepositoryLanguageStarsAction
#329 stanfordnlp/dspy Python ★ 38.4K Compare ↗
#330 istio/istio Go ★ 38.4K Compare ↗
#331 soxoj/maigret Python ★ 38.2K Compare ↗
#332 PhilJay/MPAndroidChart Kotlin ★ 38.2K Compare ↗
#333 TriliumNext/Trilium TypeScript ★ 38.2K Compare ↗
#334 aquasecurity/trivy This Project Go ★ 38.2K
#335 servo/servo Rust ★ 38.1K Compare ↗
#336 vlang/v V ★ 37.9K Compare ↗
#337 CopilotKit/CopilotKit TypeScript ★ 37.8K Compare ↗
#338 denysdovhan/wtfjs JavaScript ★ 37.7K Compare ↗
#339 eugenp/tutorials Java ★ 37.3K Compare ↗

Frequently Asked Questions

What does trivy do? +

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

What language is trivy written in? +

The primary language is Go. Topics include: containers, devsecops, docker, go, golang.

Is trivy actively maintained? +

Yes, the last recorded push was on Oct 1, 2026 with 248 open issues being tracked.

How many stars does trivy have? +

trivy has 38,167 stars and 721 forks on GitHub.

How does trivy rank among GitHub repositories? +

With 38,167 stars, aquasecurity/trivy is ranked #334 globally across all repositories tracked on GitHubRepo and #47 among Go projects.

What license is trivy distributed under? +

The repository reports a Apache-2.0 license. Always verify the repository LICENSE file for legal terms.

From our network
FOR MAINTAINERS

Built something? Put it in front of millions of developers.

We make a short reel about your project and post it across YouTube, Instagram, Threads, and X. Send a link, we do the rest.