Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk4 min

How to Scan Java Dependencies and Container Images With Trivy

Trivy scans Java archives, Maven POMs, Gradle and SBT lockfiles, and container images—but each input has different dependency and scanner coverage.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Trivy can scan Java dependency inputs—including a built JAR, a Maven POM, or supported Gradle and SBT lockfiles—and can separately scan the files and configuration in a container image. Those inputs do not produce identical results. Choose the one that matches what you want to check, and treat a clean scan as evidence only about the artifacts and checks Trivy detected, not proof that the application is secure.

Choose the Java input that matches your question

Trivy documents four Java input groups: JAR/WAR/PAR/EAR, pom.xml, *gradle.lockfile, and *.sbt.lock. The Java coverage page marks SBOM and vulnerability scanning as available for each. License detection is marked for POM and Gradle lockfiles, but not for JAR/WAR/PAR/EAR or SBT lockfiles in the documented coverage table. Check the Trivy Java coverage documentation for current release-specific coverage.

As an Amazon Associate I earn from qualifying purchases.

Input SBOM Vulnerabilities Licenses Input-specific behavior
JAR, WAR, PAR, or EAR Supported Supported Not marked in Trivy’s coverage table Includes dependencies, including development dependencies; metadata is gathered from pom.properties and MANIFEST.MF.
pom.xml Supported Supported Supported Uses Maven repositories for package information; development dependencies are excluded by default.
*gradle.lockfile Supported Supported Supported Read locally; internet access is not required to read the lockfile. Development dependencies are excluded by default.
*.sbt.lock Supported Supported Not marked in Trivy’s coverage table Local input that must be generated with the sbt-dependency-lock plugin.

Dependency-graph and source-position information are not established in the documented coverage details summarized here, so do not assume those capabilities from the file type alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scan the built artifact to inspect what you package

A JAR or other supported archive is useful when you want Trivy to inspect the assembled artifact rather than infer its contents from a build declaration. The Java documentation says archive scans include dependencies. It also identifies metadata sources as pom.properties and MANIFEST.MF, so the result depends on metadata available in the artifact.

#1 Best Overall
Scanner Bin - The Clever Document Scanning Solution
  • Flatbed scanners simply cannot compete with your smartphone and a Scanner Bin. Improved resolution and color rendering compared to popular flatbed scanners. Compare to 1200 DPI. Takes a fraction of the time to scan at a fraction of the cost. Not to mention that flatbed scanners end up adding a lot of hazardous e-waste to your local landfill.
  • Solve the common issues with smartphone scanning. Provides a contrasting background for consistent edge-detection and auto-cropping. Controls the lighting and provides stability and proper positioning while you scan with your smartphone.
  • Scan photographs, receipts, letters, notes, artwork, fragile documents, etc. Also used as an aid for the blind or visually impaired or as a document camera for remote learning. When you aren't scanning, turn on its side to use as a desk-side bin to toss in the items you want to scan later.
  • This version is the lowest cost option for a scanner solution. It is also simplified for set up and use, and therefore is recommended for those who are blind, visually impaired or have movement disorders.
  • Use with popular FREE APPS for document scanning like Adobe Scan, Scanbot, Evernote Scannable, CamScanner, and Prizmo Go

Scan a POM to analyze Maven declarations

A POM scan is not simply a local parse of a completed dependency lock. Trivy uses repositories declared in the POM under its documented repository-selection rules, with Maven Central also used for applicable release artifacts. Snapshot artifacts use configured snapshot repositories when present; other artifacts use configured release repositories when present and Maven Central. Repository lookup supplies package information; it is distinct from the vulnerability database used to identify known issues.

Use lockfiles for resolved build inputs

Gradle lockfiles are read locally, as are SBT lockfiles. This avoids the need to contact a package repository just to read those files, but it does not mean Trivy’s vulnerability database is unnecessary. For SBT, the lockfile must be produced with the sbt-dependency-lock plugin.

Account for Maven scopes and development dependencies

Trivy’s Java documentation says POM analysis includes Maven scopes import, compile, runtime, and an empty scope. Other scopes and optional dependencies are not currently analyzed. These are implementation details that can change between Trivy releases, so verify them against the version used in your workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • For POM and Gradle lockfile scans, development dependencies are excluded by default. Add --include-dev-deps when you want them included.
  • JAR/WAR/PAR/EAR scanning is documented as including development dependencies.
  • A Maven dependency may be missed or lack a usable version if its parent POM cannot be reached, a hard requirement specifies more than one version, or a dependency has no version; the Java documentation notes that child dependencies are not detected in the last case.

These differences mean that a POM, lockfile, built archive, and packaged image can produce different dependency inventories. For repeatable checks, scan the artifact relevant to the question and record the Trivy version and input used.

Scan the final container image as a separate check

Image scanning covers more than the Java dependency files. Trivy distinguishes files inside the image from image configuration metadata. For image files, vulnerability and secret scanning are enabled by default. License scanning is disabled by default; cryptographic-asset scanning is experimental, disabled by default, and uses CycloneDX output. See the container-image documentation for the current options.

Image configuration checks are a separate target. To enable misconfiguration scanning of image metadata, use --image-config-scanners misconfig. To enable metadata secret checks, the documentation shows --image-config-scanners secret. These options concern image configuration, not the files within the image.

Rank #4
Sale
Domke Small Filmguard Film Bag for Airport Xray, Lead Lined Film Roll Case
  • TRAVEL-READY FILM CONTAINER – Carry up to nine 35 mm film cassettes with confidence through airport security and customs checks. This lead-lined film container helps reduce the risk of X-ray-related fogging and streaking from low-dose carry-on screening, helping preserve unprocessed film before development
  • CARRY-ON SAFE TRAVEL USE ONLY: Always pack this lead film bag for airport xray screening inside your cabin luggage, as this protective film case is engineered for low-dose scanners only and cannot shield film from the intense, repeated X-ray exposure commonly used on checked baggage, helping serious film shooters avoid hidden damage on long trips.
  • TRIPLE-SHIELD DURABLE PROTECTION: Engineered as a rugged film case with a tough ballistic nylon exterior, dense lead‑impregnated vinyl core, and smooth snag free inner lining, this xray proof bag keeps each roll securely cushioned and easy to access, delivering dependable film storage for photographers who refuse to risk their images in transit.
  • ORGANIZED STORAGE WITH QUICK ACCESS – Keep film rolls neatly contained and ready for your next shoot with this film case's full-length hook-and-loop closure that helps block dirt, dust, and light moisture. A practical travel accessory for film photographers, analog hobbyists, and creative professionals.
  • SMALL SIZE, EVERYDAY CONVENIENCE – Measuring 5.25 x 8 in. (13 x 20 cm), this compact film container fits easily inside camera bags, backpacks, and carry-on luggage while providing dedicated storage for up to nine 35 mm film cassettes or a small camera, making it a practical travel accessory for film photography.

Misconfiguration scanning is not enabled by default for the image, fs, and repo commands. It can be combined with vulnerability and secret scanning, and is intended for configuration and infrastructure-as-code files such as Docker, Kubernetes, Terraform, and CloudFormation. The misconfiguration-scanning documentation explains the scanner’s scope.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Separate package access from vulnerability database access

For Java vulnerability findings, Trivy documents the GitHub Advisory Database for Maven. Trivy automatically fetches and caches relevant vulnerability databases during vulnerability scans; the vulnerability-scanning documentation describes the data sources and database behavior.

Best Value
Ezymivs 8PCS RFID Blocking Sleeves, Credit Card Protector, Identity Theft Protection Secure Sleeves, RFID Identity Card Protector for Men/Women Smart Slim Design Fits Wallet/Purse
  • 【RFID Signal Protection】RFID blocking sleeve is engineered with aluminum foil coating that blocks all 13.56MHz frequency signals used by skimmers. Creates a Faraday cage effect to prevent unauthorized scanning, skimming, or digital theft of your card information.
  • 【Universal Card Fit】Credit card protector holders are precisely sized at 8.7x5.8cm (3.43x2.28in) with ultra-slim 0.3mm profile to accommodate credit cards, IDs, and passports. The dimensional accuracy ensures complete coverage without bulk, seamlessly integrating into any wallet.
  • 【Durable Waterproof Composite Material】RFID wallet women card sleeves are constructed with rigid aluminum foil layered between tear-resistant polymer sheets. Provides scratch protection, water resistance, and structural integrity while maintaining flexibility for easy card insertion/removal.
  • 【Effortless Daily-Use Design】RFID identity card protector features smooth inner lining for frictionless card access and snug fit without adhesive or modifications. The minimalist design works equally well for travel security and everyday wallet organization without inconvenience.
  • 【Comprehensive Financial Document Protection】RFID card holder safeguards credit/debit cards, IDs, passports, and access cards from both electronic theft and physical damage. Essential for urban commuting, international travel, and protecting sensitive personal information.

The Java option --offline-scan affects Maven repository access, not Trivy’s vulnerability database download. Trivy still downloads its database, and dependencies unavailable locally may be skipped. Therefore, an offline Maven repository lookup is not the same as a fully network-isolated vulnerability scan: package availability and database availability are separate concerns.

Build a scan sequence around the deliverable

  1. Check the Java dependency view. Scan the POM, lockfile, or built archive that answers your question. Use a lockfile when you want to analyze that resolved input; use the built artifact when you want to inspect the assembled package.
  2. Decide whether development dependencies belong in scope. For POM and Gradle lockfile inputs, add --include-dev-deps if your policy requires them. Do not assume that the default inventory includes them.
  3. Scan the image you intend to ship. Run an image scan after packaging so findings reflect the container’s files, not only the source build declaration.
  4. Enable non-default checks deliberately. Choose license scanning or image metadata misconfiguration/secret checks when they are needed; their defaults differ from vulnerability and secret checks on image files.
  5. Review findings in context. Interpret results against the scanned input, enabled scanners, available repositories, and vulnerability database. A clean result cannot establish coverage of unsupported or unavailable dependencies.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.