Aqua News Aqua Security Allies with GitHub on Container Security

Aqua Security this week announced that its open source Trivy vulnerability scanner is now available as an Aqua Security Trivy GitHub Action, which enables DevOps teams that employ GitHub to scan both source code and dependencies built using container image for vulnerabilities.

Liz Rice, vice president of open source engineering for Aqua Security, says the collaboration with GitHub will enable IT organizations to accelerate adoption of best DevSecOps practices as they shift toward building microservice-based applications using containers.

The alliance with GitHub comes on the heels of a free open source code scanning tool dubbed CodeQL, which is being made generally available. Trivy and CodeQL are complementary in that they enable IT organizations to apply a defense-in-depth approach to DevSecOps, Rice notes.

Read more ›