Trivy
Open source
Open-source scanner for vulnerabilities, misconfigurations and secrets
The gist
Trivy scans container images, Kubernetes clusters, code repos and IaC files for vulnerabilities, misconfigurations and secrets, and it generates SBOMs. It is for developers and DevOps teams that scan their software for security issues.
The Gist, weekly