{"id":9872,"date":"2026-04-04T09:35:25","date_gmt":"2026-04-04T04:05:25","guid":{"rendered":"https:\/\/pheonixsolutions.com\/blog\/?p=9872"},"modified":"2026-09-16T17:34:28","modified_gmt":"2026-09-16T12:04:28","slug":"installing-and-setting-up-trivy-vulnerability-scanner-on-ubuntu-debian","status":"publish","type":"post","link":"https:\/\/pheonixsolutions.com\/blog\/installing-and-setting-up-trivy-vulnerability-scanner-on-ubuntu-debian\/","title":{"rendered":"Installing and Setting Up Trivy Vulnerability Scanner on Ubuntu\/Debian"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Trivy is an open-source vulnerability scanner for containers, filesystems, and Git repositories. It detects vulnerabilities, misconfigurations, and security issues in container images, packages, and infrastructure as code, and is widely used in DevOps pipelines for continuous security checks.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Implementation<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">I. Prerequisites<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ubuntu\/Debian-based Linux distribution<\/li>\n\n\n\n<li>Root or sudo privileges<\/li>\n\n\n\n<li><code>wget<\/code>, <code>apt-transport-https<\/code>, and <code>gnupg<\/code> available<\/li>\n\n\n\n<li>Internet access to reach Trivy&#8217;s official repository<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">II. How Trivy Fits Into Your Pipeline<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Trivy scans a <strong>target<\/strong> \u2014 a container image, filesystem path, or Git repository<\/li>\n\n\n\n<li>It checks that target against <strong>vulnerability databases<\/strong> it downloads and keeps updated<\/li>\n\n\n\n<li>It reports back any known CVEs, misconfigurations, or exposed secrets it finds<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2026\/04\/trivy_scan_architecture-scaled.png\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"331\" src=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2026\/04\/trivy_scan_architecture-1024x331.png\" alt=\"\" class=\"wp-image-11776\" srcset=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2026\/04\/trivy_scan_architecture-1024x331.png 1024w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2026\/04\/trivy_scan_architecture-300x97.png 300w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2026\/04\/trivy_scan_architecture-768x248.png 768w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2026\/04\/trivy_scan_architecture-1536x497.png 1536w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2026\/04\/trivy_scan_architecture-2048x663.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">III. Install Dependencies<\/h3>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo apt-get update\nsudo apt-get install -y wget apt-transport-https gnupg lsb-release\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This installs <code>wget<\/code> (download files), <code>apt-transport-https<\/code> (HTTPS repositories), <code>gnupg<\/code> (verify signatures), and <code>lsb-release<\/code> (detect your OS version).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">IV. Add the Trivy GPG Key<\/h3>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">wget -qO - https:\/\/aquasecurity.github.io\/trivy-repo\/deb\/public.key | sudo gpg --dearmor -o \/usr\/share\/keyrings\/trivy.gpg\n<\/pre>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> The original method (<code>apt-key add<\/code>) is deprecated and has been removed entirely on current Ubuntu\/Debian versions. The command above uses the current recommended approach \u2014 storing the key as a dedicated keyring file and referencing it explicitly in the repository entry (Step V), rather than adding it to a shared system-wide keyring.<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">V. Add the Trivy Repository<\/h3>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">echo \"deb [signed-by=\/usr\/share\/keyrings\/trivy.gpg] https:\/\/aquasecurity.github.io\/trivy-repo\/deb $(lsb_release -sc) main\" | sudo tee \/etc\/apt\/sources.list.d\/trivy.list\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>signed-by<\/code> flag tells <code>apt<\/code> to verify this specific repository using the keyring file from Step IV, rather than trusting any key in the system&#8217;s general keyring \u2014 a more secure, explicit approach than the older method.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">VI. Install Trivy<\/h3>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo apt-get update\nsudo apt-get install -y trivy\n<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">VII. Verify Installation<\/h3>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">trivy -v\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This confirms Trivy installed correctly and shows the installed version.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">VIII. Conclusion<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Trivy installs cleanly through its official APT repository, with the current setup using an explicit <code>signed-by<\/code> keyring reference instead of the deprecated <code>apt-key<\/code> method. Once installed, you can scan container images, filesystems, or repositories directly:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">trivy image &lt;image_name>\ntrivy fs &lt;path_to_filesystem>\n<\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why was apt-key replaced?<\/strong> <code>apt-key<\/code> trusted keys system-wide for all repositories, which was a broader security surface than necessary. The <code>signed-by<\/code> approach scopes each key to just the specific repository it&#8217;s meant to verify.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Can Trivy scan private container registries?<\/strong> Yes \u2014 Trivy supports authenticating against private registries using standard Docker credential mechanisms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does Trivy need internet access every time it runs?<\/strong> It needs access to update its vulnerability database periodically, but can run scans using a cached database if offline, as long as the database was downloaded previously.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Related Articles<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/renew-kubernetes-certificates-kubeadm\/\" target=\"_blank\" rel=\"noreferrer noopener\">How to Renew Kubernetes Certificates Using kubeadm (Step-by-Step Guide with Zero Planned Downtime)<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/how-to-configure-cert-manager-clusterissuer-with-cloudflare-api-token-on-kubernetes\/\" target=\"_blank\" rel=\"noreferrer noopener\">How to Configure cert-manager ClusterIssuer with Cloudflare API Token on Kubernetes<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Talk to our experts.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Looking for the right technology solution for your business? Our team of experts can help you with development, cloud, DevOps, design, and a wide range of other technology needs. Get in touch with our team <a href=\"https:\/\/pheonixsolutions.com\/contact\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Trivy is an open-source vulnerability scanner for containers, filesystems, and Git repositories. It detects vulnerabilities, misconfigurations, and security issues [&hellip;]<\/p>\n","protected":false},"author":508,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1024],"tags":[],"class_list":["post-9872","post","type-post","status-publish","format-standard","hentry","category-security","psol-cat-security"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/phn2x7-2ze","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/9872","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/users\/508"}],"replies":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/comments?post=9872"}],"version-history":[{"count":4,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/9872\/revisions"}],"predecessor-version":[{"id":11815,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/9872\/revisions\/11815"}],"wp:attachment":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/media?parent=9872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/categories?post=9872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/tags?post=9872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}