trivy - a scanner for vulnerabilities in container images, filesystems and git repositories, and misconfigurations in IaC
trivy <image|fs|config|repo|k8s|sbom> [flags] TARGET
Options you will use
-q, --quiet- Suppress progress bar and log output.
-d, --debug- Debug mode.
--cache-dir DIR- Cache directory (default ~/.cache/trivy).
-f, --format FORMAT- Format: table, json, template, sarif, cyclonedx, spdx, github, cosign-vuln.
-o, --output FILE- Output file name.
-s, --severity LIST- Severities of security issues to be displayed (UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL).
--exit-code INT- Exit code when issues were found (default 0: report only; CI uses 1).
--ignore-unfixed- Display only fixed vulnerabilities (ones with a patched version available).
--ignorefile FILE- Specify .trivyignore file (IDs to ignore).
--scanners LIST- List of what security issues to detect: vuln, misconfig, secret, license.
--skip-dirs LIST- Specify the directories or glob patterns to skip.
--skip-files LIST- Specify the files or glob patterns to skip.
--timeout DURATION- Timeout (default 5m0s).
--skip-db-update- Skip updating vulnerability database (offline/air-gapped runs).
Try trivy in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.