Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
First read
aquasecurity/trivy has enough public attention and recent movement to stay on the shortlist, but package usage is still partial, so the next step should be source and ecosystem validation rather than a quick yes.
37.9K public stars in the current GitStar snapshot.
Recognizable in the ecosystem
Last commit Sep 15, 2026.
Fresh activity
Treat stars as discovery context until a linked package appears.
No linked package mapping
One or more key signals are partial, so GitStar keeps the interpretation conservative.
Partial snapshot
Snapshot facts
Compare lens
gravitational/teleport and tenable/terrascan are the closest comparison targets GitStar found. A side-by-side comparison usually tells you more than a single raw rank.
Signal trail
Read the recent motion first. This block is for deciding whether the repository still looks alive, compounding, or flattening before you trust stars alone.
Package reality
No linked npm or PyPI package is mapped for this repository yet, so the page leans more heavily on GitHub-visible popularity and should be read more conservatively.
No linked package signal is expected for this project type, so the read leans more heavily on repository-level public signals.
Validation note
GitStar can summarize public signals for aquasecurity/trivy, but the GitHub repository is still the primary place to confirm release cadence, issue activity, and maintainer intent.
GitStar surfaces public popularity and package signals. These rankings are not endorsements, security reviews, or investment advice.
Why this rank
This repository stands out because it combines fresh update and stable visibility.
Reconstructed from current stars and cached daily/weekly/monthly deltas.
GitStar can see repository momentum, but it does not have a reliable linked package signal yet.
Treat stars and recent movement as discovery context only until npm or PyPI usage is available.
Shares the infrastructure category footprint with aquasecurity/trivy, so the comparison is closer to a same-problem decision than a same-language coincidence.
Shares the infrastructure category footprint with aquasecurity/trivy, so the comparison is closer to a same-problem decision than a same-language coincidence.
Shares the infrastructure category footprint with aquasecurity/trivy, so the comparison is closer to a same-problem decision than a same-language coincidence.
Shares the infrastructure category footprint with aquasecurity/trivy, so the comparison is closer to a same-problem decision than a same-language coincidence.
GitStar picked teleport + terrascan as the closest next comparison from the related repository set.
[](https://gitstar.space/repo/aquasecurity/trivy)<a href="https://gitstar.space/repo/aquasecurity/trivy"><img src="https://gitstar.space/api/badge/aquasecurity/trivy" alt="GitStar"></a>The easiest, and most secure way to access and protect all of your infrastructure.
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
A curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
This page provides a quick overview of aquasecurity/trivy based on GitStar's cached data. The signal chart reconstructs approximate checkpoints from current stars plus cached daily, weekly, and monthly star deltas, so it is best read as directional context rather than as a precise historical audit log.
Want to show your project's ranking? Copy the badge embed code above and add it to your README.