Aqua Blog

Fewer Findings, Faster Answers: How ActiveState and Trivy Turn a Scan Into a Verdict

Fewer Findings, Faster Answers: How ActiveState and Trivy Turn a Scan Into a Verdict

Trivy, the open source security scanner maintained by Aqua Security, is one of the most widely trusted tools for identifying vulnerabilities, misconfigurations, and secrets across containers, code, IaC, and Kubernetes. Millions of scans run against it every day, and for good reason: it’s fast, thorough, and gives teams visibility into risks across their development environments.

What a scan does not tell you on its own is what happened before a component reached the pipeline: where it came from, how it was built or what controls were applied upstream. Malicious open source packages grew 73% year over year in 2025, and AI coding agents are now pulling dependencies into codebases faster than most review processes can keep up with. That’s where ActiveState and Trivy complement each other: ActiveState governs and remediates components upstream, while Trivy scans the resulting artifacts and can apply ActiveState’s VEX context to its findings.

Key Takeaways

 

  • Trivy remains at the center of the scanning workflow, with ActiveState adding upstream governance and VEX context for applicable findings
  • ActiveState joined Trivy Partner Connect in November 2025, Aqua Security’s ecosystem program for bringing complementary partner capabilities and security context to Trivy users.
  • Malicious open source packages grew 73% year over year in 2025, and AI agents are pulling them in faster than manual review can catch.
  • Trivy can be configured to consume ActiveState’s VEX data, applying ActiveState’s vulnerability assessments and attribution to applicable scan results without requiring changes to application code
  • The average time to remediate a high or critical severity vulnerability is 54.8 days, which is a big part of why backlogs keep growing.

Two complementary capabilities, one software supply chain

Trivy scans containers, code, infrastructure as code, and Kubernetes for vulnerabilities and other risks. ActiveState governs open source components before they reach a build, providing packages built from source and continuously remediated against defined service levels. Neither replaces the other. Their capabilities are complementary: ActiveState addresses upstream component governance and remediation, while Trivy independently scans the resulting artifacts.

That complementary design also makes the integration low friction. Through Trivy Partner Connect, ActiveState extends the Trivy ecosystem with VEX context that Trivy can consume using its existing VEX support. Teams can add ActiveState’s vulnerability assessments to their existing Trivy scanning workflow without adopting a new scanner.

How the integration works

Trivy can scan ActiveState images and their associated SBOMs using its existing scanning capabilities. ActiveState also provides VEX data containing its vulnerability assessments. When Trivy is configured to consume that VEX data, it can filter or contextualize applicable findings according to the status and justification supplied by ActiveState. Vulnerabilities ActiveState has remediated are reflected in the updated components that Trivy scans.

The same logic holds when an AI agent, not a developer, is selecting dependencies. Point the agent’s dependency request at the ActiveState Curated Catalog instead of a public registry, and it resolves dependencies from the same governed source available to developers. Those components still pass through the existing Trivy scanning workflow, with ActiveState’s VEX context available for applicable findings.

Start with what’s already feeding your Trivy scans

If your team’s CVE backlog keeps growing, a Trivy configuration change alone won’t fix it, and it doesn’t need to. The fix is upstream: whether what’s entering your builds was vetted and remediated before Trivy ever saw it.

Learn how ActiveState brings governed open source components and VEX context into your existing Trivy scanning workflow. Explore the ActiveState + Trivy integration

FAQs
What's actually connected between ActiveState and Trivy today?

ActiveState joined Trivy Partner Connect in November 2025. Trivy scans ActiveState images and their SBOMs the same way it scans any image, and it can also be pointed at ActiveState’s public VEX repository for extra context on assessed vulnerabilities.

Do I need the Aqua Platform to use this?

No. This integration works directly with Trivy, the open source security scanner maintained by Aqua Security. Trivy is distinct from the commercial Aqua Platform, which is not required to use the ActiveState integration.

Rebecca Banks
Rebecca Banks is Senior Product Marketing Manager at ActiveState, where she leads go-to-market strategy for software supply chain security. She is currently a contributor to the Linux Foundation and OpenSSF 2026 AI Security Study on global AI coding security maturity for enterprises and critical infrastructure organizations.
Need to secure enterprise workloads?

Aqua Cloud Native Application Protection Platform (CNAPP)

Go cloud native with the experts!