Skip to content
CAI
Produce a survey ↗Verify a survey

aquasecurity/trivy

Trivy is a comprehensive, multi-format security scanner that analyzes container images, file systems, Git repositories, and virtual machines for vulnerabilities, misconfigurations, and license issues. It supports a wide array of programming languages, package managers, and operating systems, while also providing infrastructure-as-code scanning for platforms like Kubernetes, AWS, and Oracle Cloud. The system features a modular architecture that allows for extensible reporting, caching, and plugin-based execution.

73.6

Strong · 6 August 2026

109k

lines of production code

Go

primary language

4

bus factor · 554 authors in all

3

measurements over time

CAI band scale
CAI trend line

How it got here

2019–2022 · Architecture modernization and platform expansion

This period focused on a comprehensive architectural refactoring, including a migration to the Cobra CLI framework, the introduction of a modular plugin and module system, and the adoption of standard libraries for logging and caching. Concurrently, the project significantly expanded its scanning capabilities by adding support for numerous Linux distributions, container runtimes, and virtual machine images, while also introducing new reporting formats and compliance features.

131 changes

2023–2024 · IaC and dependency scanning expansion

This period focused on significantly expanding infrastructure-as-code scanning capabilities, particularly for Azure ARM templates, CloudFormation, and Terraform plan snapshots, while introducing a generic scanner for JSON/YAML/TOML files. Simultaneously, the codebase added support for a wide array of new package managers and lockfile formats, including Bun, Conda, Julia, Swift, and various Python and Node.js tools, alongside a complete rewrite of the Terraform parser and Rego scanning architecture.

148 changes

2025–2026 · scanning expansion and infrastructure hardening

This period focused on broadening vulnerability detection capabilities by adding support for new operating systems, language ecosystems, and infrastructure-as-code formats. Concurrently, the codebase underwent significant architectural refactoring to improve modularity, testability, and security, including the introduction of centralized HTTP clients, process-safe file utilities, and robust end-to-end testing frameworks.

26 changes

CAI lens gauges

Survey your own repository

aquasecurity/trivy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point the surveyor at a repository you know and see whether you agree with it.

Survey a repository

About this page

  • The description of this project is derived from its own commit history, not from its README.
  • The score is its highest published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 748a639b1d — the exact code this score is about.
  • Scored under rubric rubric-2026.08.19. Score the same commit under that rubric and you get the same number.
CAI link cards