Back to Secrets Management

Trivy

Comprehensive vulnerability scanner for containers, filesystems, git repos, and Kubernetes.

Free and open-source (Apache 2.0)

Trivy is a comprehensive and versatile security scanner by Aqua Security. It scans for vulnerabilities in container images, file systems, git repositories, Kubernetes, and IaC (Terraform, CloudFormation, Dockerfile). CNCF graduated project. Simple CLI, no daemon required. The most popular open-source container scanner.

  • Best for: Secrets Management
  • Pricing: Free and open-source (Apache 2.0)

Disclosure: We may earn a commission if you click this link and make a purchase, at no additional cost to you.

Visit Trivy

Features

✗

Audit Logging

Track all secret access and changes

✗

CI/CD Integration

Native integration with CI/CD pipelines

✗

Dynamic Secrets

Generate short-lived credentials on demand

✗

Encryption at Rest

Secrets encrypted in storage

✗

End-to-End Encryption

Client-side encryption before storage

✗

Kubernetes Integration

Native K8s secret injection

✗

Multi-Cloud Sync

Sync secrets across cloud providers

✗

RBAC

Role-based access control for secrets

✗

Secret Rotation

Automatic credential rotation on schedule

✗

Self-Hosted Option

Run on your own infrastructure

Best For

Find the right DevOps tools for your specific needs. Trivy is featured in these buying guides:

Related Links