| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Software composition analysis | Developer platform | 40% | 1 of 49 | 3% | 30 | endorsed leader |
| Container and Kubernetes security | Cloud and infrastructure | 16% | 2 of 78 | 5% | 39 | accepted challenger |
| Cloud-native application protection | Cloud and infrastructure | 0% | 15 of 57 | 0% | 6 | under 10 labels · led by Wiz at 46% |
| Vulnerability management platforms | Security operations | 0% | 76 of 80 | 50% | 6 | under 10 labels · led by Rapid7 InsightVM at 45% |
| Static application security testing | Developer platform | 0% | 42 of 47 | 0% | 1 | under 10 labels · led by Semgrep at 47% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 1 | 1 | 0 | 2 |
| GPT-5.4 mini | 0 | 4 | 0 | 1 | 5 |
| Gemini 3.5 Flash | 2 | 3 | 3 | 0 | 8 |
| Perplexity Sonar | 3 | 1 | 1 | 2 | 7 |
| Grok 4.1 Fast | 3 | 3 | 2 | 2 | 10 |
| Mistral Small | 2 | 4 | 2 | 0 | 8 |
| DeepSeek V4 Flash | 3 | 6 | 1 | 1 | 11 |
| Llama 4 Maverick | 1 | 0 | 2 | 0 | 3 |
| Qwen 3.7 Flash | 3 | 1 | 2 | 0 | 6 |
| Kimi K2 | 4 | 5 | 0 | 0 | 9 |
| GLM 4.7 FlashX | 2 | 4 | 1 | 0 | 7 |
| MiniMax M2.5 | 3 | 1 | 2 | 0 | 6 |
Verbatim evidence the judge attached to positive labels.
“the open‑source stack of Trivy + Falco + Kubescape (with NeuVector as a full‑life optional addition) provides a credible, complete container security solution” GLM 4.7 FlashX · Container security · budget prompt · first choice
“I would recommend Trivy as the default open-source dependency vulnerability scanner because it gives the broadest practical coverage in one tool” Perplexity Sonar · SCA · paraphrase prompt · first choice
“Trivy (by Aqua Security) stands out as the best software composition analysis (SCA) tool for companies with a limited budget.” Grok 4.1 Fast · SCA · budget prompt · first choice
“the best container security platform is usually Trivy if you want the lowest-cost option, because it is fully open source” Perplexity Sonar · Container security · budget prompt · first choice
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“Avoid for high-security environments until fully audited; check releases post-v0.69.4 and scan your pipelines.” Grok 4.1 Fast · SCA · negative prompt · hard negative
“Build-time scanners like Trivy, Grype, and Clair can find CVEs and misconfigurations, but they do not detect runtime threats.” Perplexity Sonar · Container security · negative prompt · soft negative
“Trivy and Nuclei are noted as strong specialized tools but with limited enterprise features or centralized management” Perplexity Sonar · Vuln management · negative prompt · soft negative
“provide a strong free foundation but lack enterprise-scale management, support, and advanced enforcement” Grok 4.1 Fast · Container security · comparative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 187 of the 224 answers that named Trivy and are not a share of its labels.
689 of the 689 domain citations in answers naming Trivy came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Trivy's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Trivy, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at trivy.dev is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.