Versions:

  • 0.69.3
  • 0.69.2
  • 0.69.1
  • 0.69.0
  • 0.68.2
  • 0.68.1
  • 0.67.2
  • 0.67.1
  • 0.67.0
  • 0.66.0
  • 0.65.0
  • 0.64.1
  • 0.64.0
  • 0.63.0
  • 0.62.1
  • 0.62.0
  • 0.61.1
  • 0.61.0
  • 0.60.0
  • 0.59.1
  • 0.59.0
  • 0.58.2
  • 0.58.1
  • 0.58.0
  • 0.57.1
  • 0.57.0
  • 0.56.2
  • 0.56.1
  • 0.56.0
  • 0.55.2
  • 0.55.1
  • 0.55.0
  • 0.54.1
  • 0.54.0
  • 0.53.0
  • 0.52.2
  • 0.52.1
  • 0.52.0
  • 0.51.4
  • 0.51.2
  • 0.51.1
  • 0.50.1
  • 0.49.1
  • 0.48.3
  • 0.48.1
  • 0.46.1
  • 0.45.1
  • 0.44.1
  • 0.43.0

Trivy 0.69.3, released by Aqua Security Software as the 49th iteration of the project, is a comprehensive security scanner engineered to detect vulnerabilities, misconfigurations, hard-coded secrets, and software bill of materials (SBOM) across containers, Kubernetes clusters, code repositories, and cloud infrastructure. Designed for DevOps and security teams who need continuous visibility into supply-chain risk, the open-source utility performs static analysis of OS packages, application dependencies, Infrastructure-as-Code templates, and running workloads without requiring pre-installed agents. Typical use cases include automated image scanning in CI/CD pipelines, nightly audits of live Kubernetes environments, pre-commit secret detection in Git repositories, and cloud account configuration reviews against CIS benchmarks; JSON and SARIF output formats allow seamless integration with issue trackers, SIEMs, and policy engines such as OPA. Operating from a single self-contained binary, Trivy supports multiple data sources—NVD, GitHub Advisories, vendor security feeds, and Aqua’s own vulnerability DB—while offering granular filtering by severity, package manager, or CVE ID. The tool is catalogued under Security & Vulnerability Scanners and is available for free on get.nero.com, where downloads are supplied through trusted Windows package sources (e.g., winget) that always deliver the latest version and support batch installation of multiple applications.

Tags: