#44 Using Trivy to Scan Your Docker Image for Security Issues
Need to scan your Docker image for security issues? Use Trivy. It’s open source, and you can run it in a Docker container, so you don’t need to install it.
Here is a one-liner that works on most operating systems. It will build the Dockerfile in the current directory and start the scan.
docker build --pull -t check-me:local . && docker run --pull=always --rm -v trivy-cache:/root/.cache/trivy -v "${PWD}:/work" aquasec/trivy:latest config /work && docker run --pull=always --rm -v trivy-cache:/root/.cache/trivy -v /var/run/docker.sock:/var/run/docker.sock aquasec/trivy:latest image --scanners vuln check-me:localYou can add --severity HIGH,CRITICAL if you want to limit the scan to high and critical findings.