Skip to main content

Menu

LEVEL 0
0/5 XP
HomeAboutTopicsPricingMy VaultStats

Categories

πŸ€– Artificial Intelligence
☁️ Cloud and Infrastructure
πŸ’Ύ Data and Databases
πŸ’Ό Professional Skills
🎯 Programming and Development
πŸ”’ Security and Networking
πŸ“š Specialized Topics
HomeAboutTopicsPricingMy VaultStats
LEVEL 0
0/5 XP
GitHub
Β© 2026 CheatGridβ„’. All rights reserved.
Privacy PolicyTerms of UseAboutContact

Trivy Vulnerability Scanner Cheat Sheet

Trivy Vulnerability Scanner Cheat Sheet

Back to Containers Orchestration
Updated 2026-05-22
Next Topic: Velero Kubernetes Backup and Disaster Recovery Cheat Sheet

Trivy is an open-source, all-in-one security scanner developed and maintained by Aqua Security, designed to find vulnerabilities, misconfigurations, secrets, and supply-chain risks across containers, filesystems, Kubernetes clusters, IaC files, and cloud accounts. Its key differentiator is breadth β€” a single binary replaces multiple specialized tools by combining CVE scanning, IaC misconfiguration detection, secret detection, SBOM generation, and license compliance in one pass. The mental model to keep in mind is that Trivy always works along two axes: a target (what you scan) and a scanner (what type of issue you look for) β€” mixing and matching them unlocks its full power.

What This Cheat Sheet Covers

This topic spans 16 focused tables and 113 indexed concepts. Below is a complete table-by-table outline of this topic, spanning foundational concepts through advanced details.

Table 1: Scan TargetsTable 2: Scanners (What Trivy Looks For)Table 3: Core CLI FlagsTable 4: Vulnerability Database ManagementTable 5: Filtering and SuppressionTable 6: Output Formats and ReportingTable 7: Misconfiguration Scanning (IaC Security)Table 8: Secret ScanningTable 9: SBOM Generation and Supply-Chain ScanningTable 10: Private Registry AuthenticationTable 11: Client/Server ModeTable 12: Trivy Operator (Kubernetes-Native Continuous Scanning)Table 13: CI/CD IntegrationTable 14: Configuration File (trivy.yaml)Table 15: Trivy vs Alternatives β€” Key DistinctionsTable 16: Common Pitfalls and False Positives

Table 1: Scan Targets

Every Trivy invocation begins with a target subcommand. Understanding what each target scans β€” and which scanners it activates by default β€” prevents missed coverage and unexpected false negatives.

CommandExampleDescription
trivy image
trivy image nginx:1.27
β€’ Scans a container image from a registry, local Docker daemon, tarball, or OCI archive for vulnerabilities, misconfigurations, and secrets
β€’ Most common entry point for container security
trivy fs
trivy fs ./myproject
Scans a local filesystem or directory for vulnerabilities in dependency files, misconfigurations, and secrets.
trivy repo
trivy repo https://github.com/org/repo
Clones and scans a remote Git repository for vulnerabilities, misconfigurations, and secrets.
trivy k8s
trivy k8s --report summary cluster
Scans a live Kubernetes cluster (current kubeconfig context), checking running workload images and K8s resource definitions.
trivy config
trivy config ./terraform/
Scans IaC configuration files only β€” Dockerfile, Kubernetes YAML, Terraform, CloudFormation, Helm, Ansible, etc.

More in Containers Orchestration

  • Tetragon eBPF Runtime Enforcement Cheat Sheet
  • Velero Kubernetes Backup and Disaster Recovery Cheat Sheet
  • Argo Rollouts and Progressive Delivery Cheat Sheet
  • Container Debugging & Troubleshooting Cheat Sheet
  • Container Storage and Persistent Volumes Cheat Sheet
  • Helm Cheat Sheet
View all 38 topics in Containers Orchestration