What is our primary use case?
I use
Trivy for scanning
Docker images and containers, as well as the entire file system to collect reports. I configure it in CI/CD pipelines.
What is most valuable?
Trivy is most valuable for its ability to scan all repository files and dependencies. Whenever vulnerabilities are found, it automatically provides solutions to resolve them. It offers integration capabilities with different solutions and is easy to configure with simple commands on the Linux operating system.
What needs improvement?
Trivy needs improvement in its user interface, and there should be more policies and signatures to detect vulnerabilities in the file system and code, as well as
Docker containers.
For how long have I used the solution?
I have worked with Trivy for over one year, approximately thirteen months.
What was my experience with deployment of the solution?
I did not face any challenges during deployment. I easily set up Trivy within 15 to 20 minutes using provided commands on their website.
What do I think about the stability of the solution?
Trivy is a very stable solution. I would rate it ten out of ten for stability.
What do I think about the scalability of the solution?
Trivy is not scalable; however, I have scanned very large projects with it. It is stable but not scalable according to my experience.
How are customer service and support?
There are times when I need technical support, which I would rate nine out of ten. I generally find support through online resources and from my seniors.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before Trivy, I used several tools for specific tasks like scanning images and code. Trivy's ability to handle multiple tasks makes it valuable.
How was the initial setup?
The initial setup was very easy. I used provided commands for installation on Linux operating systems like
RHEL and
CentOS.
What about the implementation team?
I handled the implementation myself as a DevOps Engineer.
What was our ROI?
In our IT field, security tools like Trivy are crucial. Although there was no specific ROI mentioned, having an open-source tool like Trivy is beneficial.
What's my experience with pricing, setup cost, and licensing?
Pricing and setup cost are determined by the company, so I'm not aware of the specific details.
Which other solutions did I evaluate?
I am not currently focused on exploring other tools in the DevOps space.
What other advice do I have?
Overall, I would rate Trivy nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?