Try our new research platform with insights from 80,000+ expert users
Trivy Logo

Trivy pros and cons

4.3 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the category report

Prominent pros & cons

PROS

Trivy is highly valued for its seamless integration with CI/CD pipelines.
The open-source nature and extensive functionality of Trivy are beneficial.
Trivy effectively scans AWS credentials and GCP service accounts, enhancing security.
Trivy identifies vulnerabilities in Docker images and container applications before they reach production.
The vulnerability scanning feature in Trivy supports various container capabilities like Docker and Sharma.

CONS

Reporting capabilities could be improved, especially when integrated with CI, and an output in PDF format would be beneficial.
Container image scanning is static; incorporating dynamic scanning during runtime would offer significant advantages.
Malware detection requires using two tools, Trivy and ClamAV, suggesting a need for unified management within one tool.
Lacks built-in functionality for report analysis and does not support generating reports in formats like CSV for auditing and reporting.
Generates many false positives, flagging non-existent vulnerabilities, highlighting a need for better contextual analysis or granular filtering.
 

Trivy Pros review quotes

Utsav Sharma - PeerSpot reviewer
Feb 3, 2025
The vulnerability scanning feature is excellent as it supports various container capabilities like Docker and Sharma.
Faizan Anwar - PeerSpot reviewer
Jan 30, 2025
It is open-source.
GK
Dec 24, 2024
Trivy's open source nature and wide functionality are incredibly valuable.
Find out what your peers are saying about Aqua Security, JFrog, Snyk and others in Container Security. Updated: April 2025.
849,963 professionals have used our research since 2012.
Jyothikumar C - PeerSpot reviewer
Jan 29, 2025
I can see vulnerabilities in the images of any applications deployed in the Kubernetes environment or as container applications.
reviewer2599524 - PeerSpot reviewer
Dec 4, 2024
The most valuable feature of Trivy is its easy integration with the CI/CD pipeline.
ST
Apr 25, 2025
Trivy is very reliable and always has an up-to-date database to scan images and identify vulnerabilities.
reviewer2620167 - PeerSpot reviewer
Dec 20, 2024
It's customizable, allowing me to add any rules and format HTML templates as I wish.
DK
Feb 3, 2025
I appreciate Trivy for being open-source and not requiring any payment.
DA
Jan 31, 2025
Trivy is easy to integrate with CI/CD and can be installed on desktops to scan images.
DL
Apr 28, 2025
Trivy's ability to scan files, images, GitHub repositories, Infrastructure as Code like Terraform, and Kubernetes is valuable.
 

Trivy Cons review quotes

Utsav Sharma - PeerSpot reviewer
Feb 3, 2025
Trivy generates many false positives, flagging non-existent vulnerabilities.
Faizan Anwar - PeerSpot reviewer
Jan 30, 2025
In our CI/CD pipelines, Trivy lacks built-in functionality for report analysis.
GK
Dec 24, 2024
A dynamic scanning capability during runtime would be a significant advantage.
Find out what your peers are saying about Aqua Security, JFrog, Snyk and others in Container Security. Updated: April 2025.
849,963 professionals have used our research since 2012.
Jyothikumar C - PeerSpot reviewer
Jan 29, 2025
For malware detection, I need to use two tools: Trivy as my anomaly scanner and ClamAV. I am integrating these two tools into the CI pipeline. If both malware and anomaly detection could be managed by one tool, I would not need to depend on two tools.
reviewer2599524 - PeerSpot reviewer
Dec 4, 2024
The reporting could be a little better.
reviewer2620167 - PeerSpot reviewer
Dec 20, 2024
Trivy can improve by providing an output in PDF format.
DK
Feb 3, 2025
Having little experience can hinder the ability to connect it to a user-friendly UI effectively.
DA
Jan 31, 2025
The only problem is that Trivy does not support reporting features such as generating reports in CSV, which is useful for auditing and reporting.