Try our new research platform with insights from 80,000+ expert users
Trivy Logo

Trivy pros and cons

4.3 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the category report

Prominent pros & cons

PROS

Trivy offers easy integration with CI/CD pipelines, enhancing deployment workflows.
It is open-source, providing wide functionality without requiring payment.
Users find value in its ability to scan images, files, GitHub repositories, and Infrastructure as Code.
Trivy effectively scans for vulnerabilities in applications deployed within Kubernetes and as container applications.
Trivy is praised for keeping an up-to-date database, ensuring reliable vulnerability identification.

CONS

Reporting could be enhanced, particularly for better interpretation in CI integration.
Improving output by offering PDF and CSV formats would be beneficial.
Dynamic scanning capability during runtime is needed.
Combining malware and anomaly detection into a single tool would be advantageous to avoid using multiple tools.
Trivy tends to generate many false positives, flagging non-existent vulnerabilities.
 

Trivy Pros review quotes

SK
Apr 25, 2025
What I find valuable is the ease of setup with Trivy, including pre-defined operators that require minimal configuration.
Utsav Sharma - PeerSpot reviewer
Feb 3, 2025
The vulnerability scanning feature is excellent as it supports various container capabilities like Docker and Sharma.
Faizan Anwar - PeerSpot reviewer
Jan 30, 2025
It is open-source.
Find out what your peers are saying about Aqua Security, JFrog, Snyk and others in Container Security. Updated: April 2025.
850,671 professionals have used our research since 2012.
GK
Dec 24, 2024
Trivy's open source nature and wide functionality are incredibly valuable.
SC
Apr 28, 2025
Trivy is most valuable for its ability to scan all repository files and dependencies.
Jyothikumar C - PeerSpot reviewer
Jan 29, 2025
I can see vulnerabilities in the images of any applications deployed in the Kubernetes environment or as container applications.
reviewer2599524 - PeerSpot reviewer
Dec 4, 2024
The most valuable feature of Trivy is its easy integration with the CI/CD pipeline.
ST
Apr 25, 2025
Trivy is very reliable and always has an up-to-date database to scan images and identify vulnerabilities.
reviewer2620167 - PeerSpot reviewer
Dec 20, 2024
It's customizable, allowing me to add any rules and format HTML templates as I wish.
DK
Feb 3, 2025
I appreciate Trivy for being open-source and not requiring any payment.
 

Trivy Cons review quotes

SK
Apr 25, 2025
The main area for improvement is in differentiating between OS and application-based vulnerabilities.
Utsav Sharma - PeerSpot reviewer
Feb 3, 2025
Trivy generates many false positives, flagging non-existent vulnerabilities.
Faizan Anwar - PeerSpot reviewer
Jan 30, 2025
In our CI/CD pipelines, Trivy lacks built-in functionality for report analysis.
Find out what your peers are saying about Aqua Security, JFrog, Snyk and others in Container Security. Updated: April 2025.
850,671 professionals have used our research since 2012.
GK
Dec 24, 2024
A dynamic scanning capability during runtime would be a significant advantage.
SC
Apr 28, 2025
Trivy is not scalable; however, I have scanned very large projects with it. It is stable but not scalable according to my experience.
Jyothikumar C - PeerSpot reviewer
Jan 29, 2025
For malware detection, I need to use two tools: Trivy as my anomaly scanner and ClamAV. I am integrating these two tools into the CI pipeline. If both malware and anomaly detection could be managed by one tool, I would not need to depend on two tools.
reviewer2599524 - PeerSpot reviewer
Dec 4, 2024
The reporting could be a little better.
reviewer2620167 - PeerSpot reviewer
Dec 20, 2024
Trivy can improve by providing an output in PDF format.
DK
Feb 3, 2025
Having little experience can hinder the ability to connect it to a user-friendly UI effectively.
DA
Jan 31, 2025
The only problem is that Trivy does not support reporting features such as generating reports in CSV, which is useful for auditing and reporting.