Open source
What TRUSTIVAN is built on
A security product that obscured its own supply chain would be difficult to take seriously. These are the components TRUSTIVAN depends on and the terms they come under.
Vulnerability detection
Trivy, under Apache 2.0
TRUSTIVAN's vulnerability detection is powered byTrivy, an open-source scanner developed by Aqua Security and licensed under the Apache License 2.0. We did not write it, and we say so on the front page rather than in a footnote.
The notice Apache-2.0 requires to travel with any redistribution is reproduced verbatim in the NOTICE file shipped with TRUSTIVAN:
Trivy
Copyright 2019-2020 Aqua Security Software Ltd.
This product includes software developed by Aqua Security (https://aquasec.com).
Misconfiguration policies fromtrivy-checks are covered separately by the MIT licence, © 2024 Aqua Security, and its notice travels with any build that embeds them.
Trademarks
TRUSTIVAN is not affiliated with, endorsed by, or sponsored by Aqua Security. “Trivy” and “Aqua Security” are trademarks of their respective owners. The Apache-2.0 licence grants no trademark rights, and none are claimed here.
Vulnerability data
Where the advisories come from
Findings are derived from aggregated public vulnerability feeds. The data has its own terms, separate from the licence of the code that packages it.
Sources include the National Vulnerability Database, GitHub Security Advisories, OSV, and the security trackers maintained by the Alpine, Amazon, Debian, Oracle, Photon, Red Hat, SUSE and Ubuntu projects.
Attribution and redistribution requirements differ between these feeds and are tracked separately from the code licences. If you are redistributing TRUSTIVAN or its output, read the notices that ship with it rather than relying on this summary.
Everything else
The wider dependency graph
TRUSTIVAN incorporates a further thousand-plus open-source components across the Go and npm ecosystems.
Their licences are permissive or weak-copyleft: Apache-2.0, MIT, BSD-2-Clause, BSD-3-Clause, ISC, 0BSD, MPL-2.0, BlueOak-1.0.0, CC0-1.0, CC-BY-4.0, CC-BY-SA-4.0, Python-2.0, PostgreSQL, and public domain.
No component in any distributed dependency graph is licensed under the GPL, LGPL, AGPL or SSPL. That is enforced rather than asserted: the inventory is regenerated from the installed tree and a continuous-integration gate fails the build if a strong-copyleft licence appears, or if the recorded inventory has drifted from what is actually installed.
The complete per-component inventory — with versions, detected licences, and the licence file each determination was read from — ships with the source in legal/THIRD_PARTY_NOTICES.md and legal/third-party-inventory.json.
Questions about licensing or attribution:legal@trustivan.com.