Back to Secrets Management

Trivy

Comprehensive vulnerability scanner for containers, filesystems, git repos, and Kubernetes.

Free and open-source (Apache 2.0)

Trivy is a comprehensive and versatile security scanner by Aqua Security. It scans for vulnerabilities in container images, file systems, git repositories, Kubernetes, and IaC (Terraform, CloudFormation, Dockerfile). CNCF graduated project. Simple CLI, no daemon required. The most popular open-source container scanner.

  • Best for: Secrets Management
  • Pricing: Free and open-source (Apache 2.0)

Disclosure: We may earn a commission if you click this link and make a purchase, at no additional cost to you.

Visit Trivy

Features

Audit Logging

Track all secret access and changes

CI/CD Integration

Native integration with CI/CD pipelines

Dynamic Secrets

Generate short-lived credentials on demand

Encryption at Rest

Secrets encrypted in storage

End-to-End Encryption

Client-side encryption before storage

Kubernetes Integration

Native K8s secret injection

Multi-Cloud Sync

Sync secrets across cloud providers

RBAC

Role-based access control for secrets

Secret Rotation

Automatic credential rotation on schedule

Self-Hosted Option

Run on your own infrastructure

Best For

Find the right DevOps tools for your specific needs. Trivy is featured in these buying guides:

Related Links