logo

Trivy Can Now Scan Unpackaged Binary Files

ID: c8df034b-5beb-5669-b736-250c240a8396

STIX ID: report--c8df034b-5beb-5669-b736-250c240a8396

Feed Name: Aqua Security Blog

Date Published: 2022-11-02

Date Updated: 2026-04-26

...
...

Trivy v0.33 introduces an experimental feature that enables vulnerability scanning of standalone binaries by resolving their SBOMs through Sigstore’s Rekor transparency log: Trivy computes a binary hash, queries Rekor for an attested SBOM (e.g., CycloneDX), and uses that SBOM to perform package-level vulnerability detection. The post explains the architecture and workflow, lists prerequisites and commands, and demonstrates the process with a Rust application—covering SBOM generation, attestation upload via the trivy-plugin-attest/Cosign flow, and scanning a container image with the --sbom-sources rekor flag.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.