Trivy
Purpose
Container, filesystem, repository and configuration security scanning
Decision Summary
Desk verification complete; CSI lab and internal pilot required before client production approval.
Field Notes
Authoritative official documentation reference normalized on 2026-08-04. Existing CSI classification and field evidence retained.
Backup Strategy
Back up configuration, ignore policies with justification, cached databases for offline recovery, scan reports and SBOMs. Record database versions and checksums.
Recovery Strategy
Reinstall the pinned binary/image, restore validated databases and policy configuration, rerun reference scans and compare expected results. If a bad database or release creates unreliable findings, pause enforcement and revert to the last validated scanner/database set.
Version History
2026-08-04 — Official documentation reference added/normalized.
Technology Register Metadata
- CSI Classification: Testing
- CSI Tech ID: 18
- Category: Cyber Security
- Client Approved: No
- Client Readiness: 4
- Commercial Use: Allowed
- Community: 5
- Current Version: 0.72.0
- Deployment: Docker, Native
- Deployment Simplicity: 4.5
- Docker Support: Official
- Documentation: 4.5
- Documentation URL: https://trivy.dev/latest/docs/
- Ease of Use: 4.5
- Evidence Complete: Yes
- Last Updated: July 26, 2026 10:53 PM
- Last Verified: July 25, 2026
- Licence: Apache License 2.0; commercial use allowed with licence and notice obligations.
- Lifecycle Status: In progress
- Next Review: October 25, 2026
- OS Support: Linux, Windows, macOS
- Official URL: https://trivy.dev/
- Offline Capability: 4
- Offline Support: Partial
- Overall Score: 4.4
- Performance: 4
- Security: 4.5
- Stability: 4.5
Migration Record
Imported deterministically from the CSI Technology Register.
Source classifications, approval state, risk state, version information and testing status have been preserved. No additional approval or validation has been inferred during migration.
Cyber Space Infocom
Making Technology Work for You