Trivy is a vulnerability scanner developed by Aqua Security. It scans container images, Kubernetes clusters, code repositories, and other artifacts for known security vulnerabilities (CVEs), misconfigurations, and supply chain risks. Trivy is lightweight (single binary), fast, and highly accurate. It integrates directly into CI/CD pipelines and Kubernetes clusters.