Trivy
Open source · SBOM analysis
Trivy is a general-purpose security scanner rather than an SBOM specialist. It finds vulnerabilities, misconfigurations and secrets, and produces SBOMs, across container images, Kubernetes, code repositories and cloud accounts. Teams often start here because one binary covers several jobs.
Key facts
| Vendor | Aqua Security |
|---|---|
| Licence | Apache-2.0 |
| Latest release | v0.74.0, 14 Aug 2026 |
| Repository since | 2019 |
| Does | SBOM generation, Vulnerability matching, Misconfiguration scanning, Secret scanning |
| Reads | Container images, Kubernetes, Code repositories, Cloud accounts |
| Website | trivy.dev |
| Source | github.com/aquasecurity/trivy |
Sources
Checked 21 Sept 2026. Spotted something out of date? Tell us.
Other SBOM analysis tools
Need the product tested as well? See Cyber Resilience Act compliance testing providers.