⚡
  • HOME
  • NEWS
  • SERVICES
  • ARCHITECTURE
  • TECH STACK
  • PORTFOLIO
  • ABOUT
  • CONTACT
HOMENEWSSERVICESARCHITECTURETECH STACKPORTFOLIOABOUTCONTACT
© 2026 Miodrag Gromilić. All rights reserved.
HOMENEWSSERVICESTECH STACKPORTFOLIOCONTACTABOUTFAQs
Back to Skills
Trivy

Trivy

Since 2019Comprehensive security scanner

Comprehensive security scanner — container images, filesystems, Git repos, and Kubernetes clusters in one tool.

Overview

Trivy is my primary container and infrastructure security scanner. I integrate it into CI/CD pipelines to scan Docker images for CVEs before deployment. It also scans IaC files (Terraform, Kubernetes manifests) for misconfigurations, Git repos for secrets, and running K8s clusters for vulnerabilities. Fast, accurate, and zero-config.

Use Cases

  • Container image scanning
  • IaC security
  • secret detection
  • K8s cluster scanning
  • SBOM generation
  • CI/CD security gates

Advantages

  • Fast and accurate
  • zero-config
  • comprehensive (images + IaC + secrets)
  • CI/CD friendly
  • SBOM support
  • free and open source

Considerations

  • Can produce false positives
  • database updates needed
  • limited remediation guidance
  • large vulnerability DB download

Works Great With

DockerKubernetesCI/CDTerraformJenkins

Related Technologies

SonarQube
Since 2007
OWASP ZAP
Since 2010
Snyk
Since 2015
Back to Skills CONTACT