← All cheat sheets

TRIVY

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

Comprehensive vulnerability scanner for containers, filesystems,
git repos, IaC (Terraform/CloudFormation), and Kubernetes.

INSTALLATION#

# Debian/Ubuntu
sudo apt install trivy

# macOS
brew install trivy

# Docker
docker pull aquasec/trivy

# Binary
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh

CONTAINER SCANNING#

# Scan container image
trivy image nginx:latest
trivy image python:3.11
trivy image myapp:v1.0

# Scan from Docker daemon
trivy image mylocal-image

# Scan from tar archive
trivy image --input saved-image.tar

# Severity filter
trivy image --severity CRITICAL nginx
trivy image --severity CRITICAL,HIGH nginx

# Only show fixable vulnerabilities
trivy image --ignore-unfixed nginx

# Scan specific types
trivy image --vuln-type os nginx              # OS packages only
trivy image --vuln-type library nginx         # Language libs only

# Output formats
trivy image -f json -o results.json nginx
trivy image -f table nginx                    # Default table
trivy image -f sarif -o results.sarif nginx   # SARIF for CI/CD
trivy image -f template --template "@html.tpl" -o report.html nginx
trivy image -f cyclonedx -o sbom.json nginx   # CycloneDX SBOM

FILESYSTEM SCANNING#

# Scan project directory
trivy fs .
trivy fs /path/to/project

# Scan for vulnerabilities in dependencies
trivy fs --scanners vuln .

# Scan for misconfigurations
trivy fs --scanners misconfig .

# Scan for secrets
trivy fs --scanners secret .

# All scanners
trivy fs --scanners vuln,misconfig,secret .

GIT REPOSITORY SCANNING#

# Scan remote repo
trivy repo https://github.com/user/repo

# Scan specific branch
trivy repo --branch develop https://github.com/user/repo

# Scan specific commit
trivy repo --commit abc123 https://github.com/user/repo

IAC SCANNING#

# Terraform
trivy config ./terraform/
trivy config --tf-vars terraform.tfvars ./terraform/

# CloudFormation
trivy config ./cloudformation/

# Kubernetes manifests
trivy config ./k8s-manifests/

# Dockerfile
trivy config ./Dockerfile
trivy config --file-patterns "dockerfile:Dockerfile.*" .

# Helm charts
trivy config ./charts/

KUBERNETES SCANNING#

# Scan running cluster
trivy k8s --report summary cluster

# Scan specific namespace
trivy k8s --namespace production --report all

# Scan specific resource
trivy k8s --namespace default deployment/myapp

# Scan all images in cluster
trivy k8s --report summary --scanners vuln

# Include misconfigs
trivy k8s --scanners vuln,misconfig --report all

SBOM (SOFTWARE BILL OF MATERIALS)#

# Generate SBOM
trivy image --format cyclonedx -o sbom.json nginx
trivy image --format spdx-json -o sbom.json nginx
trivy fs --format cyclonedx -o sbom.json .

# Scan existing SBOM
trivy sbom sbom.json

SECRET SCANNING#

# Scan for hardcoded secrets
trivy fs --scanners secret .
trivy image --scanners secret myapp

# Secrets detected:
#   AWS keys, GCP keys, Azure keys
#   Private keys, certificates
#   Database connection strings
#   API tokens, OAuth secrets
#   JWT secrets

FILTERING & IGNORING#

# Ignore specific CVEs
trivy image --ignore-unfixed nginx

# Ignore file (.trivyignore)
echo "CVE-2023-12345" >> .trivyignore
echo "CVE-2023-67890" >> .trivyignore
trivy image nginx

# Policy-based filtering (Rego)
trivy image --ignore-policy policy.rego nginx

CI/CD INTEGRATION#

# Exit code on findings (for CI/CD gates)
trivy image --exit-code 1 --severity CRITICAL nginx

# GitHub Actions
# - uses: aquasecurity/trivy-action@master
#   with:
#     image-ref: 'myapp:latest'
#     severity: 'CRITICAL,HIGH'
#     exit-code: '1'

# GitLab CI
# trivy image --exit-code 1 --severity CRITICAL $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA

COMMON OPTIONS#

--severity CRITICAL,HIGH,MEDIUM,LOW         # Filter by severity
--ignore-unfixed                            # Only fixable vulns
--exit-code 1                               # Non-zero exit on findings
--timeout 10m                               # Scan timeout
--cache-dir /path/to/cache                  # Custom cache
--skip-db-update                            # Skip DB update
--offline-scan                              # No network access
--quiet                                     # Minimal output
--debug                                     # Debug output

TIPS#

  - --severity CRITICAL,HIGH for actionable results
  - --ignore-unfixed to focus on fixable issues
  - Use SARIF output for GitHub/GitLab security tabs
  - CycloneDX SBOM for supply chain compliance
  - Scan both images AND filesystem for full coverage
  - Secret scanning catches hardcoded credentials
  - IaC scanning prevents misconfig before deployment
  - Cache DB locally (--cache-dir) for faster CI/CD scans
  - Combine with Grype for cross-validation
  - Use .trivyignore for accepted risk CVEs

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.