RapidFort and Aqua Security Partner to Enhance Aqua Trivy Scanner with RapidFort Curated Images, Advisories and Remediation Data
Trivy Connect Partnership Enables Development and Security Teams to Start with Near-zero CVE Images, Reduce Operational
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.
![]()
RapidFort, the leader in Software Supply Chain Security (SSCS) with the largest distribution of curated truly open-source software, today announced its new partnership with Aqua Security, the company delivering Aqua Trivy, a comprehensive, open-source cloud native security scanner that unifies vulnerability detection, misconfiguration scanning, and secret identification across the entire software development lifecycle.
Under Trivy Partner Connect, Trivy integrates RapidFort security advisories, enabling it to accurately report the status of packages in RapidFort Curated Images. This includes access to enhanced information including when RapidFort uses fixes extracted from other distributions or adapted from otherwise incompatible versions to patch affected packages. This new integration ensures Trivy recognizes each fix and is able to accurately report the near-zero CVE status of RapidFort Curated Images.
As a result, development and security teams can start with near-zero CVE images, reduce the operational burden of vulnerability management, and spend less time sorting through scanner noise. Instead of managing false positives, developers can focus on building and releasing their products with greater confidence.
“Joint customers benefit from more accurate vulnerability results, less noise, and greater confidence in the security of the images they deploy,” said Matt Richards, Chief Operating Officer at Aqua Security. “RapidFort brings differentiated remediation capabilities and a level of advisory detail that enables Trivy to recognize packages RapidFort has already patched even when those fixes are sourced from other distributions or adapted from versions that would otherwise be incompatible. By combining Trivy’s trusted open-source scanning with RapidFort near-zero CVE images and transparent remediation data, we are helping development and security teams spend less time investigating false positives and more time delivering secure software.”
Even when an application is well-built, teams can spend countless hours chasing vulnerabilities in base images, dependencies, libraries, and operating system packages, many of which turn out to be false positives or already mitigated in ways traditional scanners do not understand. RapidFort Curated Images shift vulnerability elimination left without shifting more work onto developers. Combined with Trivy’s support for RapidFort advisories, teams get cleaner third-party scan results, more accurate security posture, and a faster path from development to production.
“Trivy is one of the most downloaded open-source security scanners, and we are pleased to partner with Aqua Security to enhance the productivity of developers, who get a true assessment of security risks and can now focus on development without worrying about fixing CVEs,” said George Manuelian, Chief Strategy Officer at RapidFort. “RapidFort is truly transparent about its curated images and enables partners to accurately assess images for any CVE risks. Partnering with companies like Aqua Security gives developers confidence that they are working with up to 99.9 percent CVE-free code before applications are ever deployed into production.”
This new integration is generally available immediately. Schedule a demo here https://www.rapidfort.com/schedule-a-call.
About RapidFort
RapidFort leads the Software Supply Chain Security market with the largest distribution of curated, genuinely open-source software. Its platform enables organizations to eliminate risk at scale through hardened near-zero CVE container images, runtime profiling, attack surface management, and the industry’s first independently malware-scanned open-source images – cutting CVE exposure by up to 99.9% without code changes or platform migration. RapidFort is recognized in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security, named a Gartner® Cool Vendor™, and honored as a Nutanix .Next Partner of the Year. The company is backed by Blue Cloud Ventures and Forgepoint Capital and headquartered in Sunnyvale, Calif. Visit www.RapidFort.com.
RapidFort, RAPIDFORT, and RBOM are registered trademarks of RapidFort, Inc. All other marks and names mentioned herein may be trademarks of their respective companies.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260929894248/en/
Media gallery

