# aquasecurity/trivy > Security scanner that finds vulnerabilities, misconfigurations, secrets and SBOM in containers, Kubernetes, code repositories, clouds and filesystems. Aimed at developers and DevOps for checking artifact security. - Magnitude: 1.6 out of 10 — Steady - Stars: 38,010 total · +8 stars today, ≈ 14 by evening - Star trust: star growth looks organic - Category: Security · Language: Go · License: Apache-2.0 · Created: 2019-04-11 · Last push: 2026-09-22 - GitHub: https://github.com/aquasecurity/trivy · Homepage: https://trivy.dev · Page: https://gitnova.dev/en/r/aquasecurity/trivy ## Useful for - Scan a Docker image for known CVEs before deployment - Scan a Kubernetes cluster for misconfigurations and secrets - Integrate scanning into CI via GitHub Actions ## Why it’s here - 8 stars so far today, about 14 expected by the end of the day. - GitHub Trending Go today: #14, +11 stars. ## Star trust Star growth looks organic. - Fewer forks than usual: 707 for 38,010 stars. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 707 - Issues and pull requests: 8,111 - Watchers: 226 - Average over the last week: 14 per day - Usual pace: 16 per day - Stars in the last hour (measured): 1 - Latest release: v0.74.0 (2026-08-14) ## Stars per day, last 30 days (oldest → newest, today is partial) 2026-08-24 … 2026-09-22: 21, 16, 33, 25, 14, 10, 13, 19, 15, 21, 26, 14, 9, 20, 16, 13, 11, 12, 11, 14, 14, 17, 19, 20, 19, 13, 11, 7, 12, 8 ## Spotted in now - GitHub Trending Go today: #14, +11 stars ## Similar by description 1. **anchore/syft** — 1.0 · Steady · Security · Go · +2 stars today, ≈ 4 by evening A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images, filesystems, and archives. Supports many packaging ecosystems and output formats (CycloneDX, SPDX). Full card: https://gitnova.dev/en/r/anchore/syft.md 2. **nmatt0/mithril** — 0.8 · Cooling · Security · C++ · +2 stars today, ≈ 4 by evening C++ static scanner for firmware and IoT software: finds embedded secrets and keys, builds an SBOM, matches components against CVEs, and detects licenses, fully offline and emitting JSON. Full card: https://gitnova.dev/en/r/nmatt0/mithril.md 3. **trufflesecurity/trufflehog** — 1.4 · Cooling · Security · Go · +4 stars today, ≈ 8 by evening TruffleHog is a Go tool for finding leaked credentials: it scans Git, chats, wikis, logs and filesystems, classifies secrets across 800+ types, and verifies whether they are still live. It is aimed at security teams and developers… Full card: https://gitnova.dev/en/r/trufflesecurity/trufflehog.md 4. **projectdiscovery/nuclei** — 2.0 · Steady · Security · Go · +12 stars today, ≈ 22 by evening A vulnerability scanner driven by YAML templates that checks applications, APIs, networks, DNS and cloud configurations for known vulnerabilities. Community-contributed templates mimic real-world exploitation steps to reduce false… Full card: https://gitnova.dev/en/r/projectdiscovery/nuclei.md 5. **perplexityai/bumblebee** — 0.7 · Quiet · Security · Go · +0 stars today, ≈ 1 by evening A Go tool that scans developer machines for supply-chain exposure by reading on-disk package, extension, and MCP config metadata and matching it against a catalog of known compromises. Full card: https://gitnova.dev/en/r/perplexityai/bumblebee.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-09-22 13:19 UTC, updated every 30 minutes.