RapidFort, the leader in Software Supply Chain Security with the largest distribution of curated truly open-source software, today announced its new partnership with Aqua Security, the company delivering Aqua Trivy, a comprehensive open-source cloud native security scanner. RapidFort's new Trivy Connect partnership enables development and security teams to start with near-zero CVE images, reduce operational burden of vulnerability management, and spend less time sorting through scanner noise.
Under Trivy Partner Connect, Trivy integrates RapidFort security advisories, enabling it to accurately report the status of packages in RapidFort Curated Images. This includes access to enhanced information including when RapidFort uses fixes extracted from other distributions or adapted from otherwise incompatible versions to patch affected packages. This new integration ensures Trivy recognizes each fix and is able to accurately report the near-zero CVE status of RapidFort Curated Images.
Even when an application is well-built, teams can spend countless hours chasing vulnerabilities in base images, dependencies, libraries, and operating system packages, many of which turn out to be false positives or already mitigated in ways traditional scanners do not understand. RapidFort Curated Images shift vulnerability elimination left without shifting more work onto developers. Combined with Trivy's support for RapidFort advisories, teams get cleaner third-party scan results, more accurate security posture, and a faster path from development to production.
As a result, development and security teams can start with near-zero CVE images, reduce the operational burden of vulnerability management, and spend less time sorting through scanner noise. Instead of managing false positives, developers can focus on building and releasing their products with greater confidence.
Trivy unifies vulnerability detection, misconfiguration scanning, and secret identification across the entire software development lifecycle. RapidFort's platform enables organizations to eliminate risk at scale through hardened near-zero CVE container images, runtime profiling, attack surface management, and independently malware-scanned open-source images.
This new integration is generally available immediately, helping joint customers achieve more accurate vulnerability results and greater confidence in the security of images they deploy.
About RapidFort
RapidFort leads the Software Supply Chain Security market with the largest distribution of curated, genuinely open-source software. Its platform enables organizations to eliminate risk at scale through hardened near-zero CVE container images, runtime profiling, attack surface management, and the industry's first independently malware-scanned open-source images – cutting CVE exposure by up to 99.9% without code changes or platform migration. RapidFort is recognized in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security, named a Gartner® Cool Vendor™, and honored as a Nutanix .Next Partner of the Year. The company is backed by Blue Cloud Ventures and Forgepoint Capital and headquartered in Sunnyvale, Calif.