๐ trivy-plugin-report
็ฎไฝไธญๆ
๐ trivy-plugin-report is a plugin that can convert Trivy's output in JSON format into an EXCEL file.
๐ค Why is it needed?
Trivy can output reports in various formats, but these reports are more suitable for technical personnel
to study and fix vulnerabilities.
In many business scenarios, we also need to present security risks in a more understandable way
to non-technical personnel, making EXCEL files particularly important.
๐ Features
- Trivy Compatibility: Supports JSON format reports generated by Trivy.
- Office Friendly: Converts to EXCEL format, suitable for non-technical personnel to read and report.
๐ ๏ธ Installation
trivy plugin install github.com/y4ney/trivy-plugin-report
๐ Usage
trivy image --format json -d --output plugin=report [--output-plugin-arg plugin_flags] <image_name>
OR
trivy image -f json <image_name> | trivy report [plugin_flags]
๐ Common Usage
-
Generate an EXCEL table and name it output.xlsx
trivy image -f json debian:12 | trivy report --excel-file output.xlsx

-
Use --beautify to beautify the EXCEL file, that is, fill in the background color according to
the severity of the vulnerabilities.
trivy image -f json debian:12 | trivy report --excel-file output-beautify.xlsx --beautify

TODO
- ๐ Export markdown file
- ๐ Localize the report to Chinese
- ๐ Add Alibaba vulnerability source
- ๐ Add CNNVD vulnerability source
- ๐ก๏ธ Support for misconfiguration, license, and secret