Project reference ↗

A team needs visibility into vulnerabilities and configuration findings in the workloads already present in its cluster. Trivy Operator coordinates security scanning in Kubernetes and publishes reports that can feed triage and remediation workflows. It helps keep that inventory connected to cluster resources, but producing a report does not automatically prevent a deployment. Decide who responds to findings, how scans authenticate to registries and how the scanner itself is trusted and updated, including review of relevant security advisories.

It is a current candidate for teams revisiting old container-scanner pages, including Aqua MicroScanner, whose repository documents its deprecation.

Decide how reports are used

Define scan scope, database-update access, registry authentication, exclusions and report retention. A report is useful only when a team owns triage and remediation. Separate a known package vulnerability from demonstrated exploitability in the running application, and avoid treating an empty report as proof of safety.

Adoption checks

Check the Trivy scanner image separately from the operator. Aqua’s March 2026 advisory identifies malicious v0.69.4 artifacts and Docker Hub v0.69.5/v0.69.6 images during defined exposure windows; it does not establish that the operator itself was compromised. Audit pulled, mirrored and cached scanner artifacts against the advisory. If an affected scanner ran, treat accessible credentials as potentially exposed and follow upstream response guidance. Consult current advisories when choosing a replacement version.

Evaluate scanner resource use and permissions on a noncritical namespace first. Include a private image, an unavailable registry and a database-update failure. Keep build-time scanning and admission decisions explicit; the presence of an operator is not automatically a deployment gate.

The scanner guide places Trivy alongside SBOM generation, signing and runtime detection. These controls answer different questions and need different response owners.

Sources & further reading

  1. Official Helm installation
  2. MicroScanner deprecation
  3. Trivy Operator scanner image and scope configuration
  4. Trivy March 2026 supply-chain advisory

Spotted something that needs another look?

Help improve this page →