HomeSecurity & encryption tools › Trivy

Trivy

All-in-one vulnerability & misconfig scanner

provisional — pending verificationApache-2.0self-hostable
Arete score
4.5 / 5
Autonomy5
Return5
Efficiency4
Transparency4
ἀρετή “AH-reh-tay” — excellence: a thing being good at what it’s for. Mean of the four principle scores. How we score →

Plain outbound link — no affiliate parameters, no tracking redirects.

~ Provisional — seeded estimate by a human researcher; full rubric pass pending. Working notes ↓

Why it's listed

Trivy is listed in security & encryption tools because it competes on utility: all-in-one vulnerability & misconfig scanner. Its funding model is disclosed on the listing. Licensed Apache-2.0; pricing: free. Technically it's lean — it runs comfortably on modest hardware, which is exactly the proof-of-work efficiency we rank for. This entry is provisional — the scores are seeded estimates pending our full manual rubric pass, and the verification date will appear here once complete.

Facts

License
Apache-2.0
Pricing
Free
Funding model
Aqua Security OSS
Self-hostable
Yes
Verification
Provisional — scores are seeded estimates pending manual verification

Evidence notes

Candidate for our v2 verification pipeline

Recorded during the rubric pass — every score must carry evidence a stranger could re-check.

Also in security & encryption tools

Spotted a problem — trackers added, dark patterns, abandonment? Report a violation. Scores change when evidence does.