Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Trivy v0.75.0 shipped with a major addition: cryptographic asset scanning now integrated into the image command, capable of detecting crypto vulnerabilities and outputting results in CycloneDX format. Alongside crypto support, the release included fixes for Python tooling (uv workspace lockfiles,…
Get this in your inbox every Monday →A deterministic 0–100 hygiene score — README, license, CI, tests, docs, and freshness.
Who ships this repo — author concentration and the bus factor across the last 300 mainline commits.
How welcoming this repo is to contributors — issue throughput, close time, responsiveness, and good-first-issue count.
What this project is built on — dependency count by ecosystem, the license mix, and anything worth a legal look before you adopt it.
Whether this project's CI can be trusted — pass rate, run times, flaky runs, and which workflow is the weak link.
Grounded in trivy's README, structure, and recent commits — answers won't invent code they haven't seen.
A Monday email with what shipped, in plain English — no account needed.
Showing raw commit titles for the newest commits. Sign in to generate AI summaries.
docs(kubernetes): fix --exclude-namespace flag name in scan example (#10935)
ci(helm): bump Trivy version to 0.75.0 for Trivy Helm Chart 0.27.0 (#11334)
fix(os): keep the fullest OS version when merging analyzer results (#11039)
feat(echo): add vulnerability detection for Echo-patched Python packages (#10555)
feat(crypto): transfer cryptographic assets in client/server mode (#11141)
A floor, not a guess: counts only commits whose author, co-author trailer, or message explicitly credits an AI tool (Claude, Copilot, Cursor, aider, Codex…). Based on 30 mainline commits. Unattributed AI code isn't counted here — the full audit estimates that separately.