Configures and runs Trivy for container image scanning: Aqua Security's all-in-one scanner combining vuln + secret + misconfiguration + license detection in one pass; `trivy image {image}` with --severity HIGH,CRITICAL filter; --format sarif/json (incl. scan-embedded CycloneDX; for standalone SBOM generation see syft-generation + cyclonedx-format); .trivyignore CVE suppression file; --ignore-unfixed for actionable filter; --scanners vuln/misconfig/license/secret toggle. Use when the team wants a single tool covering container image security across multiple dimensions, not for producing a standalone CycloneDX SBOM.
75
94%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Medium
Suggest reviewing before use
Per trivy.dev/latest/docs/target/container_image/:
Trivy is Aqua Security's open-source scanner. Distinguishing
feature: all-in-one - one CLI invocation covers vuln + secret +
misconfig + license scanning. By contrast, syft-generation
grype-scanning is a two-step
SBOM-then-scan pattern.Per tv-img the scanner toggles:
| Scanner | Default? | Use |
|---|---|---|
vuln | yes | Known CVEs in OS + language packages |
secret | yes | Exposed credentials (env vars, config files) |
misconfig | no | Docker / Kubernetes config best-practices |
license | no | License compliance scanning |
grype-scanning for
cross-DB consensus on vuln findings.Common install paths:
# Homebrew (macOS / Linux)
brew install trivy
# Docker (zero-install for CI)
docker pull aquasec/trivy:latest
# Linux APT
sudo apt-get install trivy
# RPM
sudo dnf install trivyPer tv-img:
# Default: vuln + secret scan
trivy image python:3.4-alpineExample with multiple toggles:
# All scanners (vuln + secret + misconfig + license)
trivy image --scanners vuln,secret,misconfig,license python:3.4-alpine
# Vuln-only (fastest, default if --scanners omitted defaults to vuln+secret)
trivy image --scanners vuln python:3.4-alpinePer tv-img:
trivy image --severity HIGH,CRITICAL python:3.4-alpineSeverity levels: UNKNOWN, LOW, MEDIUM, HIGH, CRITICAL.
Combined with exit-code-on-finding:
trivy image --severity HIGH,CRITICAL --exit-code 1 python:3.4-alpineExit code semantics: 0 = no findings at the configured severity;
1 = findings present.
Per tv-img:
| Format | Use |
|---|---|
json | For multi-scanner finding prioritization |
sarif | GitHub Code Scanning upload |
cyclonedx | CycloneDX SBOM with vuln annotations |
spdx-json | SPDX SBOM (vuln-only metadata) |
template | Custom Go template |
| (default) | Table format human-readable |
trivy image --format json --output trivy-image.json my-image:1.0
trivy image --format sarif --output trivy-image.sarif my-image:1.0
trivy image --format cyclonedx --output trivy-cyclonedx.json my-image:1.0--ignore-unfixed for actionable filterPer tv-img, --ignore-unfixed excludes vulnerabilities without an
available fix - the practical first-line filter for actionable findings:
trivy image --ignore-unfixed python:3.4-alpineCombine with a severity threshold for the recommended PR-blocking config (fail only on actionable, high-severity vulns):
trivy image --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1 my-image:1.0Per tv-img:
"Secret detection runs automatically. The tool scans for exposed credentials and sensitive data, particularly in environment variables."
Secret findings appear alongside vuln findings in the same report.
For deeper secret-scanning patterns, see gitleaks-scanning
trufflehog-scanning
in the qa-secrets plugin.Per tv-img:
trivy image --scanners misconfig --severity HIGH,CRITICAL my-image:1.0Detects Docker / Kubernetes config patterns matching CIS Benchmarks
For comprehensive IaC scanning (not just image-internal config),
use checkov-policy
tfsec-policy
from the qa-iac plugin.Per tv-img: "Use a .trivyignore file to suppress
specific findings. Place this file in your project directory with
CVE IDs or vulnerability identifiers you wish to exclude."
Suppression mechanisms:
| Mechanism | Use |
|---|---|
.trivyignore file | Per-CVE / per-misconfig-rule ID list |
--ignore-unfixed flag | Filter to actionable findings only |
--vex (VEX file) | Standardized status assertions (CycloneDX-VEX or OpenVEX) |
--ignore-policy Rego policy | Programmatic ignore via OPA Rego |
.trivyignore example:
# .trivyignore
# Reason: log4j-core 2.14.x bundled but not loaded at runtime
# (verified via dependency tree analysis)
# Approved-by: alice@example.com
# Re-review-date: 2026-09-15
CVE-2021-44228
CVE-2021-45046
# Misconfiguration ignores
DS013
KSV001Justification template (mandatory): every entry in .trivyignore
should be preceded by # Reason: ... # Approved-by: ... # Re-review-date: ...
comment block.
For richer programmatic suppression, use OpenVEX:
trivy image --vex sbom.openvex.json --severity HIGH,CRITICAL my-image:1.0The VEX file's per-CVE assertions (not_affected etc.) filter the
output.
Cadence: every quarter, audit .trivyignore; expired re-review-date
entries removed.
Wrap the CLI with the aquasecurity/trivy-action GHA to scan the built image
and upload SARIF to GitHub Code Scanning. The full GitHub Actions workflow is
in references/ci-and-composition.md.
Trivy is the all-in-one first line; compose it with syft-generation for a
standalone SBOM, grype-scanning for cross-DB consensus on findings, and
checkov-policy for deeper IaC scanning. The full composition table is in
references/ci-and-composition.md.
| Anti-pattern | Why it fails | Fix |
|---|---|---|
Skip --ignore-unfixed | Stuck findings (no fix available) flood report | Always for PR gating (Step 5) |
.trivyignore without justification comment | No audit trail | Mandatory template (Step 8) |
| Run all scanners on every PR | Slow; misconfig + license noise on small changes | Default vuln+secret on PR; full scan nightly |
| Skip severity filter | LOW noise drowns CRITICAL signal | --severity CRITICAL,HIGH for PR (Step 3) |
Pin to aquasec/trivy:latest Docker tag | Breaking changes mid-release | Pin specific version |
grype-scanning for cross-DB
consensus.--vex flag)syft-generation,
grype-scanning,
cyclonedx-format,
spdx-format - sister tools