Trivy + AppGuard
Comprehensive vulnerability scanner for containers, filesystems, and Git repositories. Covers OS packages and language dependencies.
What is Trivy?
Trivy is a comprehensive and versatile security scanner by Aqua Security. It can find vulnerabilities, misconfigurations, secrets, and SBOM in containers, filesystems, git repositories, Kubernetes, and more. Trivy is the most popular open source vulnerability scanner for containers, with support for all major package managers and operating systems.
Integrate Trivy with AppGuard
Install Trivy
Install Trivy via the official install script or Docker.
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
Scan a container image
Run Trivy against a container image or filesystem.
trivy image --format sarif -o results.sarif nginx:latest
Push to AppGuard
Send the SARIF results to your AppGuard instance.
curl -X POST "$APPGUARD_PUBLIC_URL/api/ingest" \ -H "X-Api-Token: $API_TOKEN" \ -F "[email protected]"
What AppGuard adds to Trivy
Unified vulnerability view
See container vulnerabilities alongside application-level SAST and SCA findings.
Severity trending
Track vulnerability counts over time to measure improvement.
Webhook alerts
Get notified when critical container vulnerabilities are detected.