All Tools
T
Dev ToolsFreeOpen Source
TRIVY
Vulnerability and misconfig scanner for images and K8s
Apache-2.0
ABOUT
CUDA and Python images ship with stale OS packages and leaked keys, and cluster YAML often has open RBAC. Trivy scans images, filesystems, repos, and Kubernetes for CVEs, secrets, and misconfigurations in one CLI so training images fail CI before they hit a GPU node.
INSTALL
brew install trivyINTEGRATION GUIDE
1. Scan CUDA training images for OS and Python CVEs in CI
2. Detect secrets and API keys committed in an ML repo
3. Audit Kubernetes RBAC and pod security for an inference cluster
4. Generate SBOMs for model-serving images before a production release
TAGS
securitycontainerssbomcvekubernetesscanningopen-source