---
title: "Trivy Specialists | Dedicated Security Team | Azendo"
description: "Trivy for scanning container images, IaC and SBOMs in the pipeline, plus the dedicated Azendo specialists who work with it. Part of a managed team."
url: "https://azendo.co/skills/trivy/"
---

1. [Home](https://azendo.co/)
2. [Skills](https://azendo.co/skills/)
3. Trivy

# Trivy specialists for your dedicated team.

Trivy is an open-source security scanner from Aqua Security. One binary scans container images, filesystems, Git repositories and Kubernetes clusters for known vulnerabilities, misconfigurations in infrastructure-as-code, exposed secrets and licences, and it can generate and scan software bills of materials in CycloneDX and SPDX formats.

## Where Trivy fits in a long-term product team.

Breadth in one tool is the reason to choose Trivy. The same command checks an image before it is pushed, a Terraform directory for an open security group, and a repository for a committed key, and with a cached database it runs fast enough to sit in every pipeline. Its SBOM output records exactly what went into each release, which helps when a new vulnerability is published and the question is which images contain the affected package.

Failing the build on every finding is the usual mistake. Base images carry operating system packages with known issues that have no fix yet, and a gate that blocks on those blocks every release. Filtering to issues with a fix available, setting severity thresholds, and keeping a reviewed ignore file with reasons gives a gate that holds. Small, regularly rebuilt base images cut the findings at the source.

## What your dedicated team does with Trivy.

Images built months ago keep running long after their packages pick up new vulnerabilities. Scanning the registry, such as Amazon ECR or Azure Container Registry, and the running cluster on a schedule, as well as at build time, is how those are found. The Trivy Operator does the cluster part inside Kubernetes, and each finding still needs someone to rebuild, redeploy and confirm.

That loop between the pipeline, the registry and the cluster belongs with a DevSecOps engineer who stays on the product, as part of a [dedicated security engineering team](https://azendo.co/services/dedicated-cybersecurity-team/).

## Common Trivy use cases.

* A gate before images are pushed Vulnerabilities with a fix available block the build, and the rest are reported.
* Infrastructure code checked in review Terraform, Kubernetes manifests and Dockerfiles scanned for misconfigurations before they are applied.
* An SBOM for every release A record of each image's contents, so a newly published vulnerability can be traced to the releases it affects.

## Adding Trivy skills to your team.

Scanning across the pipeline, the registry and the cluster is set up and maintained within one committed monthly capacity across the security discipline.

You can add Trivy capacity as one dedicated specialist or as part of a wider remote team, managed by a service delivery manager from our offices in Thailand. Companies [hire dedicated developers](https://azendo.co/hire-a-dedicated-development-team-in-thailand/) this way under one agreement and one monthly fee.

## Roles that use Trivy

* [Cloud Security Engineer Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/cloud-security-engineer/)
* [DevSecOps Engineer Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/devsecops-engineer/)

## Disciplines it belongs to

* [Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/)

Capacity is agreed across your whole team, with one monthly fee, not per skill.

## Related in security

* [OWASP Top 10, a skill in our teams](https://azendo.co/skills/owasp-top-10/)
* [threat modelling, a skill in our teams](https://azendo.co/skills/threat-modelling/)
* [Burp Suite, a skill in our teams](https://azendo.co/skills/burp-suite/)
* [OWASP ZAP, a skill in our teams](https://azendo.co/skills/owasp-zap/)
* [Semgrep, a skill in our teams](https://azendo.co/skills/semgrep/)
* [Snyk, a skill in our teams](https://azendo.co/skills/snyk/)
* [HashiCorp Vault, a skill in our teams](https://azendo.co/skills/hashicorp-vault/)

## Tell us what your roadmap needs Trivy for.

A service delivery manager will reply with the specialists we'd suggest, the monthly capacity and what the first month looks like.

[Browse all skills](https://azendo.co/skills/)
