Trivy Skills
Comprehensive security scanner for containers, filesystems, and IaC. Find vulnerabilities, misconfigurations, and secrets.
4 skills
Trivy CI/CD Pipeline Integration
Integrate Trivy scanning into CI/CD pipelines with GitHub Actions — container scanning, IaC scanning, SBOM generation, and security gate enforcement with SARIF uploads.
Container Image Vulnerability Scanning
Scan container images for OS and application vulnerabilities with Trivy — severity filtering, SBOM generation, VEX for false positive management, registry authentication, CI gating, and supply chain security patterns.
Infrastructure as Code Security Scanning
Scan Terraform, CloudFormation, Kubernetes YAML, and Dockerfiles for security misconfigurations with Trivy — severity filtering, custom Rego policies, CI gate integration, SARIF output, and compliance frameworks.
Vulnerability Scanner
> Think like an attacker, defend like an expert. 2025 threat landscape awareness.