ActiveOSI-approved OSSSecuritySecurity Scanning

Trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Data confidence90/100
Source coverage86/100
Publish confidence88/100
Evidence checkedJul 31, 2026
Score Breakdown

Public signal read

?

How to read this

These bars are a reader-facing view of the ToolVitals evidence model. They summarize maintenance, shipping, confidence, and decay signals.

Activity
Recent commits, releases, changelog, package, and product-motion signals.
Reliability
Maintenance posture from recency, release evidence, availability, and repo signals.
Adoption
Public footprint from GitHub stars, forks, and watchers when available.
Sustainability
Longer-term posture combining health, activity, adoption, confidence, and decay risk.
ToolVitals85/100Health87/100Shipping75/100Zombie Risk0/100
Overall Score85Active
Activity75
Reliability87
Adoption86
Sustainability85

Score History

Scores collected daily. More data points appear as the tracker runs.

About this tool

What ToolVitals knows about Trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

This tool has an OSI-approved open-source license signal.

Maintenance and shipping signals are strong.

Source-visible projectSecurity ScanningOSI-approved OSSScored Intelligence
Repository

GitHub Activity

Go
aquasecurity/trivy
Stars37,147
Forks560
Watchers37,147
Open Issues236
Primary Language
Go
Last Commit
Today
Releases 90d
4
Default Branch
main
License
Apache-2.0
Repository Status
Active repository
Evidence

Signal Quality

Data Confidence90/100Strong
Source Coverage86/100Strong
Publish Confidence88/100Strong

ConfidenceHigh-confidence score from multiple public signals.

Zombie RiskNo meaningful zombie signal right now.

How ToolVitals scores work
Openness

License Evidence

Class
OSI-approved OSS
License
Apache-2.0

This tool has an OSI-approved open-source license signal.

Sources

Tracked Sources

Profile

Classification

Category
Security
Use Case
Security Scanning
Openness
OSI-approved OSS
License
Apache-2.0
Tool Mode
Source-visible project
Score Model
Open Source Maintenance
Score Visibility
Scored Intelligence
Status
Active
Maintainers

README Badge

Show this ToolVitals status in project docs.

Open badge SVG
Latest

Recent Updates

Tags
open-sourcecontainersdevsecopsdockergogolanghacktoberfestiacinfrastructure-as-codekubernetesmisconfigurationsecuritysecurity-toolsvulnerabilityvulnerability-detectionvulnerability-scannersvulnerability-scanningcontainer-scanningkubernetes-securityiac-scanningmisconfiguration-scanningsecret-scanningsbom

Recommended Alternatives

Top-ranked tools in the same use case by public ToolVitals evidence.

DefectDojo

Active · OSI-approved OSS

97

Snyk

Active · OSI-approved OSS

95

Kubescape

Active · OSI-approved OSS

94

Some links are affiliate links. ToolVitals may earn a commission from qualifying purchases.