Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Trivy can scan Java dependency files and packaged artifacts, as well as files and configuration inside container images. The right input depends on what you need to check: a Maven POM or build lockfile describes dependencies, a JAR or WAR represents a built artifact, and an image scan examines the packaged filesystem. These inputs do not provide identical dependency or license coverage, and some checks require explicit options.
Choose the Java input that matches what you build
Trivy documents four Java input groups: JAR/WAR/PAR/EAR artifacts, Maven pom.xml, Gradle *gradle.lockfile, and SBT *.sbt.lock. The available scan results differ by input type.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Java Security (2nd Edition) | $33.56 | Buy on Amazon |
| 2 |
|
Software Security for Developers: With examples in Java and Spring | $59.99 | Buy on Amazon |
| 3 |
|
Spring Security in Action, Second Edition | $50.00 | Buy on Amazon |
| 4 |
|
Java Security Solutions | $103.82 | Buy on Amazon |
| 5 |
|
Learn Java the Easy Way: A Hands-On Introduction to Programming | $21.27 | Buy on Amazon |
| Input | SBOM | Vulnerabilities | Licenses | Dependencies and practical notes |
|---|---|---|---|---|
| JAR, WAR, PAR, or EAR | Supported | Supported | Not listed as supported in the Java coverage table | Includes dependencies, including development dependencies. Trivy gathers JAR metadata by parsing pom.properties and MANIFEST.MF. |
Maven pom.xml |
Supported | Supported | Supported | Trivy resolves package information through repositories declared in POM files and Maven Central according to artifact and repository rules. Development dependencies are excluded by default. |
Gradle *gradle.lockfile |
Supported | Supported | Supported | Read locally; the lockfile does not require internet access. Development dependencies are excluded by default. |
SBT *.sbt.lock |
Supported | Supported | Not listed as supported in the Java coverage table | Read locally; the lockfile must be generated with the sbt-dependency-lock plugin. |
These capabilities and qualifications are from Trivy’s Java coverage documentation; command behavior can change between Trivy releases. Use the file your build actually produces rather than assuming a source manifest and a packaged artifact will yield the same dependency inventory.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Scan a Maven project
From the project directory, scan its POM for vulnerabilities:
#1 Best Overall
trivy fs --scanners vuln pom.xml
For Maven, Trivy analyzes dependencies in the import, compile, runtime, and empty scopes. Other scopes and optional dependencies are not currently analyzed. Package resolution uses repositories declared in the POM and Maven Central under documented rules: snapshot artifacts use configured snapshot repositories when present; other artifacts use configured release repositories when present and Maven Central.
Dependency discovery can be incomplete when a parent POM is unreachable or a hard requirement contains multiple possible versions. Trivy also does not detect child dependencies when a dependency has no version. These are documented implementation details and may change in later releases.
Include development dependencies when needed
For POM and Gradle lockfile scans, development dependencies are excluded by default. Add --include-dev-deps when the scan should cover them:
trivy fs --scanners vuln --include-dev-deps pom.xml
JAR/WAR/PAR/EAR scanning includes development dependencies according to the Java coverage table. That distinction can make the artifact scan’s inventory differ from a POM or lockfile scan.
Scan a built artifact or lockfile
Use the artifact or lockfile path as the filesystem target. For example:
trivy fs --scanners vuln target/application.jar
trivy fs --scanners vuln gradle.lockfile
trivy fs --scanners vuln dependencies.sbt.lock
Replace the example paths with the files produced by your project. Gradle and SBT lockfiles are local inputs; the SBT lockfile must come from the specified plugin. Trivy’s Java coverage table supports SBOM and vulnerability scanning for these input types, but does not list license scanning for JAR-family or SBT lockfile inputs.
Rank #3
Understand vulnerability data and offline scans
Trivy lists the GitHub Advisory Database for Maven as a Java vulnerability source. During vulnerability scans, it automatically fetches, maintains, and caches relevant vulnerability databases; see Trivy’s vulnerability scanning documentation.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallMaven repository access and vulnerability database availability are separate concerns. The Java documentation says --offline-scan prevents connections to Maven repositories, but does not prevent Trivy from downloading its vulnerability database. Dependencies unavailable on the local machine may be skipped in offline mode. Therefore, offline scanning is not a promise that every dependency will be analyzed without network access.
Scan the final container image
An image scan examines files in the image, not just the project’s original build files. Trivy enables vulnerability and secret scanning for image files by default. License scanning is disabled by default; cryptographic-asset scanning is experimental, disabled by default, and uses CycloneDX output. The documented image behavior is described in Trivy’s container image documentation.
Rank #4
- Used Book in Good Condition
Scan an image by its name and tag:
trivy image my-java-app:1.0
Change the example to the image reference you built or intend to deploy. The image scan complements a POM or lockfile scan: it evaluates the packaged image’s contents, which can differ from the dependency declarations in source.
Distinguish image files from image configuration
Trivy treats the image filesystem and image metadata as separate targets. Vulnerability and secret scanning of image files are enabled by default, but metadata checks for misconfiguration and secrets are disabled by default. To enable image-configuration misconfiguration checks, use:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →trivy image --image-config-scanners misconfig my-java-app:1.0
To scan image configuration for secrets, use --image-config-scanners secret. These options target image metadata; they do not mean that all checks for the image filesystem are enabled.
Best Value
Misconfiguration scanning is also not enabled by default for the image, fs, and repo commands. Trivy’s scanner focuses on configuration and infrastructure-as-code files, including Docker, Kubernetes, Terraform, and CloudFormation. The misconfiguration scanning documentation describes combining scanners, for example vulnerability, misconfiguration, and secret checks. Select checks for the target you are scanning rather than assuming a default scan covers every category.
Build a practical Java-to-image workflow
- Choose a dependency input. Scan the POM when you need Maven dependency resolution, a Gradle or SBT lockfile when that is your project’s dependency record, or a built JAR/WAR when you want to inspect the packaged Java artifact.
- Set development-dependency coverage deliberately. For Maven and Gradle lockfile scans, add
--include-dev-depsif those dependencies belong in the assessment. Do not assume the default inventory includes them. - Scan the built image as a separate check. Run
trivy image my-java-app:1.0against the image you plan to deliver. This checks the image’s files and is not interchangeable with analyzing the project’s POM. - Enable additional checks explicitly. Use the documented image configuration option for metadata misconfiguration or secret checks. Account separately for license scanning and experimental cryptographic-asset scanning, which are not enabled by default.
- Plan for data and repository access. Ensure Trivy can obtain its vulnerability database. For Maven, also consider whether repository access is available;
--offline-scancan leave dependencies unavailable locally unexamined.
A scan reports detected issues based on the supported inputs, enabled scanners, and available data. A clean result is not proof that an application or image is secure, especially when dependencies could not be resolved or a check was not enabled.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

