cd/entity/Trivy· home entities Trivy
grep -l @trivy /news/*.json | wc -l → 17

Trivy

mentions 17 type Organization feed RSS

// recent coverage 17 mentions

13:00
2026-08-17
docker.com
ai-policy

Make zero CVEs your new default

Docker AI Governance now streams every policy decision into the SIEM that security teams already use, providing a searchable record in Docker Cloud. The update follows a year in which supply-chain att…

21:04
2026-08-16
socket.dev
ai-agents

How AI Agents Expand the Software Supply Chain Attack Surface

Socket founder and CEO Feross Aboukhadijeh told AI Council 2026 that AI agents are expanding the software supply chain attack surface by selecting dependencies, connecting to MCP servers, installing s…

14:18
2026-08-13
echo.ai
ai-infrastructure

We eliminated 1,400 CVEs in NanoClaw's container images

Echo, in partnership with NanoClaw, eliminated 1,400 CVEs from NanoClaw's container images by using vulnerability scanners, upgrading safe libraries, backporting patches, and replacing the base OS wit…

12:02
2026-08-11
csoonline.com
ai-safety

GitHub already has an EDR. You just have to listen to it

Researchers Yossi Weizman of Microsoft and Mor Weinberger of Echo presented at Black Hat USA 2026 a new open-source tool, 'GitHub Threat Detector,' that uses GitHub's own event stream to detect supply…

09:54
2026-08-05
github.com
developer-tools

How HN: Argus – open-source security scanner with MCP

Argus, an open-source security scanner that orchestrates 20+ industry-standard tools including Semgrep, Trivy, Gitleaks, tfsec, Checkov, and OWASP ZAP behind a single command and an MCP server, is now…

12:10
2026-07-12
byteiota.com
ai-tools

DockSec: Fix Docker Vulnerabilities, Not Just Find Them

DockSec, an OWASP Incubator Project, launches to bridge the gap between vulnerability detection and remediation in Docker containers by orchestrating Trivy, Grype, and Docker Scout scanners with an LL…

09:06
2026-05-28
dev.to
ai-tools

vens-action: reranking Trivy/Grype CVEs by real risk in CI

Vens Labs has released vens-action, a GitHub Action that reranks Trivy and Grype CVE scan results by actual business risk rather than generic CVSS scores. The tool reads scan output alongside a YAML c…

22:48
2026-05-22
dev.to
developer-tools

9 in 10 Docker Compose files skip the basic security flags

According to the article, a security audit of 6,444 public Docker Compose files found that approximately 90% of them are missing three basic security flags: `read_only: true`, `cap_drop: [ALL]`, and `…

// co-occurs with top 8 entities
// topics top 6 topics