TRIVY
Comprehensive vulnerability scanner for containers, filesystems, git repos, IaC (Terraform/CloudFormation), and Kubernetes.
INSTALLATION#
# Debian/Ubuntu sudo apt install trivy # macOS brew install trivy # Docker docker pull aquasec/trivy # Binary curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh
CONTAINER SCANNING#
# Scan container image trivy image nginx:latest trivy image python:3.11 trivy image myapp:v1.0 # Scan from Docker daemon trivy image mylocal-image # Scan from tar archive trivy image --input saved-image.tar # Severity filter trivy image --severity CRITICAL nginx trivy image --severity CRITICAL,HIGH nginx # Only show fixable vulnerabilities trivy image --ignore-unfixed nginx # Scan specific types trivy image --vuln-type os nginx # OS packages only trivy image --vuln-type library nginx # Language libs only # Output formats trivy image -f json -o results.json nginx trivy image -f table nginx # Default table trivy image -f sarif -o results.sarif nginx # SARIF for CI/CD trivy image -f template --template "@html.tpl" -o report.html nginx trivy image -f cyclonedx -o sbom.json nginx # CycloneDX SBOM
FILESYSTEM SCANNING#
# Scan project directory trivy fs . trivy fs /path/to/project # Scan for vulnerabilities in dependencies trivy fs --scanners vuln . # Scan for misconfigurations trivy fs --scanners misconfig . # Scan for secrets trivy fs --scanners secret . # All scanners trivy fs --scanners vuln,misconfig,secret .
GIT REPOSITORY SCANNING#
# Scan remote repo trivy repo https://github.com/user/repo # Scan specific branch trivy repo --branch develop https://github.com/user/repo # Scan specific commit trivy repo --commit abc123 https://github.com/user/repo
IAC SCANNING#
# Terraform trivy config ./terraform/ trivy config --tf-vars terraform.tfvars ./terraform/ # CloudFormation trivy config ./cloudformation/ # Kubernetes manifests trivy config ./k8s-manifests/ # Dockerfile trivy config ./Dockerfile trivy config --file-patterns "dockerfile:Dockerfile.*" . # Helm charts trivy config ./charts/
KUBERNETES SCANNING#
# Scan running cluster trivy k8s --report summary cluster # Scan specific namespace trivy k8s --namespace production --report all # Scan specific resource trivy k8s --namespace default deployment/myapp # Scan all images in cluster trivy k8s --report summary --scanners vuln # Include misconfigs trivy k8s --scanners vuln,misconfig --report all
SBOM (SOFTWARE BILL OF MATERIALS)#
# Generate SBOM trivy image --format cyclonedx -o sbom.json nginx trivy image --format spdx-json -o sbom.json nginx trivy fs --format cyclonedx -o sbom.json . # Scan existing SBOM trivy sbom sbom.json
SECRET SCANNING#
# Scan for hardcoded secrets trivy fs --scanners secret . trivy image --scanners secret myapp # Secrets detected: # AWS keys, GCP keys, Azure keys # Private keys, certificates # Database connection strings # API tokens, OAuth secrets # JWT secrets
FILTERING & IGNORING#
# Ignore specific CVEs trivy image --ignore-unfixed nginx # Ignore file (.trivyignore) echo "CVE-2023-12345" >> .trivyignore echo "CVE-2023-67890" >> .trivyignore trivy image nginx # Policy-based filtering (Rego) trivy image --ignore-policy policy.rego nginx
CI/CD INTEGRATION#
# Exit code on findings (for CI/CD gates) trivy image --exit-code 1 --severity CRITICAL nginx # GitHub Actions # - uses: aquasecurity/trivy-action@master # with: # image-ref: 'myapp:latest' # severity: 'CRITICAL,HIGH' # exit-code: '1' # GitLab CI # trivy image --exit-code 1 --severity CRITICAL $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
COMMON OPTIONS#
--severity CRITICAL,HIGH,MEDIUM,LOW # Filter by severity --ignore-unfixed # Only fixable vulns --exit-code 1 # Non-zero exit on findings --timeout 10m # Scan timeout --cache-dir /path/to/cache # Custom cache --skip-db-update # Skip DB update --offline-scan # No network access --quiet # Minimal output --debug # Debug output
TIPS#
- --severity CRITICAL,HIGH for actionable results - --ignore-unfixed to focus on fixable issues - Use SARIF output for GitHub/GitLab security tabs - CycloneDX SBOM for supply chain compliance - Scan both images AND filesystem for full coverage - Secret scanning catches hardcoded credentials - IaC scanning prevents misconfig before deployment - Cache DB locally (--cache-dir) for faster CI/CD scans - Combine with Grype for cross-validation - Use .trivyignore for accepted risk CVEs
TRIVY CHEATSHEET ================= Source: https://cheatsheet.johlem.net Comprehensive vulnerability scanner for containers, filesystems, git repos, IaC (Terraform/CloudFormation), and Kubernetes. INSTALLATION ------------- # Debian/Ubuntu sudo apt install trivy # macOS brew install trivy # Docker docker pull aquasec/trivy # Binary curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh CONTAINER SCANNING -------------------- # Scan container image trivy image nginx:latest trivy image python:3.11 trivy image myapp:v1.0 # Scan from Docker daemon trivy image mylocal-image # Scan from tar archive trivy image --input saved-image.tar # Severity filter trivy image --severity CRITICAL nginx trivy image --severity CRITICAL,HIGH nginx # Only show fixable vulnerabilities trivy image --ignore-unfixed nginx # Scan specific types trivy image --vuln-type os nginx # OS packages only trivy image --vuln-type library nginx # Language libs only # Output formats trivy image -f json -o results.json nginx trivy image -f table nginx # Default table trivy image -f sarif -o results.sarif nginx # SARIF for CI/CD trivy image -f template --template "@html.tpl" -o report.html nginx trivy image -f cyclonedx -o sbom.json nginx # CycloneDX SBOM FILESYSTEM SCANNING --------------------- # Scan project directory trivy fs . trivy fs /path/to/project # Scan for vulnerabilities in dependencies trivy fs --scanners vuln . # Scan for misconfigurations trivy fs --scanners misconfig . # Scan for secrets trivy fs --scanners secret . # All scanners trivy fs --scanners vuln,misconfig,secret . GIT REPOSITORY SCANNING -------------------------- # Scan remote repo trivy repo https://github.com/user/repo # Scan specific branch trivy repo --branch develop https://github.com/user/repo # Scan specific commit trivy repo --commit abc123 https://github.com/user/repo IAC SCANNING -------------- # Terraform trivy config ./terraform/ trivy config --tf-vars terraform.tfvars ./terraform/ # CloudFormation trivy config ./cloudformation/ # Kubernetes manifests trivy config ./k8s-manifests/ # Dockerfile trivy config ./Dockerfile trivy config --file-patterns "dockerfile:Dockerfile.*" . # Helm charts trivy config ./charts/ KUBERNETES SCANNING --------------------- # Scan running cluster trivy k8s --report summary cluster # Scan specific namespace trivy k8s --namespace production --report all # Scan specific resource trivy k8s --namespace default deployment/myapp # Scan all images in cluster trivy k8s --report summary --scanners vuln # Include misconfigs trivy k8s --scanners vuln,misconfig --report all SBOM (SOFTWARE BILL OF MATERIALS) ------------------------------------ # Generate SBOM trivy image --format cyclonedx -o sbom.json nginx trivy image --format spdx-json -o sbom.json nginx trivy fs --format cyclonedx -o sbom.json . # Scan existing SBOM trivy sbom sbom.json SECRET SCANNING ----------------- # Scan for hardcoded secrets trivy fs --scanners secret . trivy image --scanners secret myapp # Secrets detected: # AWS keys, GCP keys, Azure keys # Private keys, certificates # Database connection strings # API tokens, OAuth secrets # JWT secrets FILTERING & IGNORING ----------------------- # Ignore specific CVEs trivy image --ignore-unfixed nginx # Ignore file (.trivyignore) echo "CVE-2023-12345" >> .trivyignore echo "CVE-2023-67890" >> .trivyignore trivy image nginx # Policy-based filtering (Rego) trivy image --ignore-policy policy.rego nginx CI/CD INTEGRATION ------------------- # Exit code on findings (for CI/CD gates) trivy image --exit-code 1 --severity CRITICAL nginx # GitHub Actions # - uses: aquasecurity/trivy-action@master # with: # image-ref: 'myapp:latest' # severity: 'CRITICAL,HIGH' # exit-code: '1' # GitLab CI # trivy image --exit-code 1 --severity CRITICAL $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA COMMON OPTIONS ---------------- --severity CRITICAL,HIGH,MEDIUM,LOW # Filter by severity --ignore-unfixed # Only fixable vulns --exit-code 1 # Non-zero exit on findings --timeout 10m # Scan timeout --cache-dir /path/to/cache # Custom cache --skip-db-update # Skip DB update --offline-scan # No network access --quiet # Minimal output --debug # Debug output TIPS ----- - --severity CRITICAL,HIGH for actionable results - --ignore-unfixed to focus on fixable issues - Use SARIF output for GitHub/GitLab security tabs - CycloneDX SBOM for supply chain compliance - Scan both images AND filesystem for full coverage - Secret scanning catches hardcoded credentials - IaC scanning prevents misconfig before deployment - Cache DB locally (--cache-dir) for faster CI/CD scans - Combine with Grype for cross-validation - Use .trivyignore for accepted risk CVEs
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.