Seismograph

What’s gaining stars on GitHub right now

aquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

SecurityGo#security#security-tools#docker#containers#vulnerability-scanners
1.6 Steady Magnitude out of 10 — how fast interest is growing, not a quality score. Star growth looks organic. Data as of September 22, 2026, 12:33 UTC.
Open on Seismograph Open on GitHub

About the project

Security scanner that finds vulnerabilities, misconfigurations, secrets and SBOM in containers, Kubernetes, code repositories, clouds and filesystems. Aimed at developers and DevOps for checking artifact security.

Useful for

README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.

Why it’s trending

Stars per day

02550June 25, 2026September 22, 2026

Bars are daily stars, the line is the usual pace. Red marks spike days.

Numbers

Total stars
38,010
Today
8 · ≈ 14 by evening
Forks
707
Issues and pull requests
8,111
Watchers
226
Language
Go
License
Apache-2.0
Latest release
v0.74.0 · August 14, 2026
Created
April 11, 2019
Last push
September 22, 2026

Star trust

Star growth looks organic. The magnitude is lowered, not zeroed:

  • Fewer forks than usual: 707 for 38,010 stars.

These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.

Spotted in

Share

README badge

Paste it into your README — the badge shows the current magnitude and links to this page.

Seismograph: 1.6
[![Seismograph](https://gitnova.dev/badge/aquasecurity/trivy.svg?lang=en)](https://gitnova.dev/en/r/aquasecurity/trivy)

Similar by description

  1. 1.1
    anchore/syft

    A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images, filesystems, and archives. Supports many packaging ecosystems and output formats (CycloneDX, SPDX).

    SteadySecurityGo+2 stars today, ≈ 4 by evening

  2. 0.8
    nmatt0/mithril

    C++ static scanner for firmware and IoT software: finds embedded secrets and keys, builds an SBOM, matches components against CVEs, and detects licenses, fully offline and emitting JSON.

    CoolingSecurityC+++2 stars today, ≈ 4 by evening

  3. 1.4
    trufflesecurity/trufflehog

    TruffleHog is a Go tool for finding leaked credentials: it scans Git, chats, wikis, logs and filesystems, classifies secrets across 800+ types, and verifies whether they are still live. It is aimed at security teams…

    CoolingSecurityGo+4 stars today, ≈ 9 by evening

  4. 2.0
    projectdiscovery/nuclei

    A vulnerability scanner driven by YAML templates that checks applications, APIs, networks, DNS and cloud configurations for known vulnerabilities. Community-contributed templates mimic real-world exploitation steps to…

    SteadySecurityGo+12 stars today, ≈ 23 by evening

  5. 0.7
    perplexityai/bumblebee

    A Go tool that scans developer machines for supply-chain exposure by reading on-disk package, extension, and MCP config metadata and matching it against a catalog of known compromises.

    QuietSecurityGo+0 stars today, ≈ 1 by evening

  6. 1.5
    wazuh/wazuh

    Open source security platform with endpoint agents and a management server: intrusion detection, log analysis, file integrity monitoring, vulnerability detection and incident response.

    SteadySecurityC+++2 stars today, ≈ 6 by evening