aquasecurity/trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
About the project
Security scanner that finds vulnerabilities, misconfigurations, secrets and SBOM in containers, Kubernetes, code repositories, clouds and filesystems. Aimed at developers and DevOps for checking artifact security.
Useful for
- Scan a Docker image for known CVEs before deployment
- Scan a Kubernetes cluster for misconfigurations and secrets
- Integrate scanning into CI via GitHub Actions
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 8 stars so far today, about 15 expected by the end of the day.
- GitHub Trending Go today: #14, +11 stars.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 38,010
- Today
- 8 · ≈ 14 by evening
- Forks
- 707
- Issues and pull requests
- 8,111
- Watchers
- 226
- Language
- Go
- License
- Apache-2.0
- Latest release
- v0.74.0 · August 14, 2026
- Created
- April 11, 2019
- Last push
- September 22, 2026
Star trust
Star growth looks organic. The magnitude is lowered, not zeroed:
- Fewer forks than usual: 707 for 38,010 stars.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 22, 2026GitHub Trending Go today: #14, +11 stars
Similar by description
-
1.1
anchore/syft
A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images, filesystems, and archives. Supports many packaging ecosystems and output formats (CycloneDX, SPDX).
-
0.8
nmatt0/mithril
C++ static scanner for firmware and IoT software: finds embedded secrets and keys, builds an SBOM, matches components against CVEs, and detects licenses, fully offline and emitting JSON.
-
1.4
trufflesecurity/trufflehog
TruffleHog is a Go tool for finding leaked credentials: it scans Git, chats, wikis, logs and filesystems, classifies secrets across 800+ types, and verifies whether they are still live. It is aimed at security teams…
-
2.0
projectdiscovery/nuclei
A vulnerability scanner driven by YAML templates that checks applications, APIs, networks, DNS and cloud configurations for known vulnerabilities. Community-contributed templates mimic real-world exploitation steps to…
-
0.7
perplexityai/bumblebee
A Go tool that scans developer machines for supply-chain exposure by reading on-disk package, extension, and MCP config metadata and matching it against a catalog of known compromises.
-
1.5
wazuh/wazuh
Open source security platform with endpoint agents and a management server: intrusion detection, log analysis, file integrity monitoring, vulnerability detection and incident response.