Cybersecurity · head to head
Semgrep vs Syft

Semgrep
Cybersecurity
Open-source static analysis tool for finding security bugs and enforcing code standards.
- From
- Free
- Rated
- -

Syft
Cybersecurity
Generates a software bill of materials from images, filesystems and archives
- From
- Free
- Rated
- -
The short version
- Each has a real cost: Semgrep free tier caps out at 10 contributors and 10 repositories.; Syft lockfile parsing can drop packages silently. An open issue filed in August 2026 reports the yarn v1 cataloguer returning 118 of 745 packages with no error raised, which means a complete bill of materials and an 84 percent incomplete one look identical to the caller.
- They diverge on capability: Semgrep covers Static code scanning, Syft covers Multi-format output.
- Prices and features above were last checked on 31 August 2026.
Where they differ
Only the attributes on which Semgrep and Syft actually diverge.
Identical on both: starting price (Free), free tier (Yes), user rating (Not yet rated), category (Cybersecurity).
What each one covers
Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.
Only in Semgrep
- Static code scanning
- Supply chain scanning
- Secrets detection
- Cross-file analysis
- AI-powered triage and remediation
- CI/CD integration
Only in Syft
- Multi-format output
- Broad ecosystem coverage
- Binary classifiers
- In-toto attestations
- Library and CLI
- Pairs with Grype
What people use each for
The jobs each tool is most often brought in to do.
Semgrep
- Scanning code for security vulnerabilities in CI/CDnot Syft
- Detecting vulnerable open-source dependenciesnot Syft
- Finding hardcoded secrets before code shipsnot Syft
- Enforcing custom code standards with rule setsnot Syft
- Prioritizing findings with AI-assisted triagenot Syft
Syft
- Producing a bill of materials for a customer or regulator that requires onenot Semgrep
- Feeding an inventory into a vulnerability scanner rather than scanning images directlynot Semgrep
- Recording what shipped in a build so a future disclosure can be answered quicklynot Semgrep
- Public sector work where an SBOM is a contractual deliverablenot Semgrep
Where each one falls short
Documented limitations, not opinions. Every one is a constraint you would hit in normal use.
Semgrep
- Free tier caps out at 10 contributors and 10 repositories.
- Secrets scanning is priced as a separate module ($15/contributor) from Code and Supply Chain.
- Self-managed repositories and custom CI/CD require the Enterprise tier.
- AI credits are limited per tier and additional usage requires upgrading.
Syft
- Lockfile parsing can drop packages silently. An open issue filed in August 2026 reports the yarn v1 cataloguer returning 118 of 745 packages with no error raised, which means a complete bill of materials and an 84 percent incomplete one look identical to the caller.
- Fidelity varies sharply by ecosystem. Conan for C and C++, Haskell and Terraform get cataloguer support with no licence data, no dependency relationships and no file ownership, so a C and C++ shop gets the least from it.
- Binary classification yields no licence or dependency metadata, and vendored or statically linked code is exactly where supply chain risk hides, so the blind spot and the risk overlap.
- Incorrect CPE values and CPE collisions are recorded as open issues, and since Grype matches on CPE and PURL, an inventory error becomes a false negative in the security report downstream.
- An inventory is not a risk assessment. Even a perfect bill of materials says a vulnerable version is present, never that the vulnerable function is called, and the triage burden lands entirely on the reader.
Pricing, plan by plan
Semgrep
Free- FreeFree
- Up to 10 contributors
- Code and Supply Chain scanning
- 60 AI credits total
- Teams$30/month
- Code, Supply Chain, or Secrets scanning per contributor
- Pro rules
- AI-powered triage and remediation
- Enterprise$undefined/month
- On-prem support
- Custom CI/CD
- 50 AI credits per developer/month
Syft
Free- SyftFree
- Apache-2.0
- No usage limits
- Community support
- Anchore Enterprise$undefined/year
- Policy enforcement and reporting
- Federal and commercial tiers
- Pricing not published, quoted on request
Which should you pick?
Choose Semgrep if
- You need static code scanning.
- You want to start without paying.
- You work on web, api, linux, mac, windows.
- You also want supply chain scanning.
Choose Syft if
- You need multi-format output.
- You want to start without paying.
- You work on macOS, Linux, Windows, Docker.
- You also want broad ecosystem coverage.
Questions people ask
- Is Semgrep or Syft better?
- Neither clearly leads. Semgrep starts at Free and Syft at Free, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
- Which is cheaper, Semgrep or Syft?
- Semgrep starts at Free and Syft at Free.
- Does Semgrep or Syft run on more platforms?
- Semgrep runs on web, api, linux, mac, windows. Syft runs on macOS, Linux, Windows, Docker.
- Can I use Semgrep for free?
- Both have a free tier, so you can try either at no cost before committing.
- What is Semgrep best used for?
- Semgrep is most often used for scanning code for security vulnerabilities in ci/cd, detecting vulnerable open-source dependencies, finding hardcoded secrets before code ships, enforcing custom code standards with rule sets. Of those, scanning code for security vulnerabilities in ci/cd and detecting vulnerable open-source dependencies are not what Syft is typically brought in for.
- What can Semgrep do that Syft cannot?
- Semgrep covers Static code scanning, Supply chain scanning, Secrets detection, Cross-file analysis. Syft covers Multi-format output, Broad ecosystem coverage, Binary classifiers, In-toto attestations.
Answered from the vendors’ own pages
Semgrep: What does Semgrep cost?
The Free edition covers up to 10 contributors; Teams starts at $30/contributor/month for Code scanning (Supply Chain also $30, Secrets $15); Enterprise is custom-priced.
SourceSyft: Does Syft find vulnerabilities?
No. It produces an inventory. Grype, from the same company, matches that inventory against vulnerability feeds. They are separate tools and the distinction is frequently lost.
Semgrep: Is there a free plan, and what are its limits?
Yes, the Free edition supports up to 10 contributors and 10 repositories with Code and Supply Chain scanning plus 60 AI credits total.
SourceSyft: Does anything in the Anchore stack do reachability analysis?
No. Neither Syft, Grype nor the commercial Anchore platform performs call graph or reachability analysis, so none of them tells you whether a vulnerable code path is actually invoked.
Semgrep: How is usage metered?
Pricing is per contributor, defined as someone who made at least one commit to a scanned private repository in the past 90 days.
SourceSyft: Is it a CNCF or OpenSSF project?
No. It is single-vendor open source owned by Anchore, with no foundation governance. That is a different licence risk profile from Sigstore.
Semgrep: Is there special pricing for startups?
Yes, Semgrep offers special startup pricing upon request for early-stage companies.
SourceSyft: What does Anchore Enterprise cost?
Not published. The pricing page is contact-sales only, with named but unpriced commercial and federal tiers.
Syft: How do I know my SBOM is complete?
You largely cannot, which is the honest answer. Silent partial parsing is a known open defect, so a bill of materials used for compliance should be spot-checked against a known dependency list.
Related pages
Other head to heads
- Semgrep vs Veracode
- Semgrep vs Arnica
- Semgrep vs Trivy
- Semgrep vs Grype
- Semgrep vs Snyk
- Semgrep vs Bitwarden
- Semgrep vs Infisical
- Semgrep vs Chainguard
- Semgrep vs Authelia
- Semgrep vs HashiCorp Vault
- Semgrep vs Ory Kratos
- Semgrep vs authentik
- Semgrep vs SentinelOne Singularity
- Semgrep vs Shufti Pro
- Semgrep vs Signicat
- Semgrep vs Silent Eight
- Semgrep vs Socket
- Semgrep vs Socure
- Semgrep vs Cosign
- Semgrep vs Sigstore
- Semgrep vs Metasploit
- Semgrep vs Wireshark
- Semgrep vs Legit Security
- Semgrep vs OWASP ZAP
- Semgrep vs Tenable Nessus
- Semgrep vs Transmit Security
- Semgrep vs TrustArc
- Semgrep vs Varonis Data Security Platform
- Semgrep vs VMware Carbon Black
- Syft vs Veracode
- Syft vs Arnica
- Syft vs Trivy
- Syft vs Grype
- Syft vs Snyk
- Syft vs Bitwarden
- Syft vs Infisical
- Syft vs Chainguard
- Syft vs Authelia
- Syft vs HashiCorp Vault
- Syft vs Ory Kratos
- Syft vs authentik
- Syft vs SentinelOne Singularity
- Syft vs Shufti Pro
- Syft vs Signicat
- Syft vs Silent Eight
- Syft vs Socket
- Syft vs Socure
- Syft vs Cosign
- Syft vs Sigstore
- Syft vs Metasploit
- Syft vs Wireshark
- Syft vs Legit Security
- Syft vs OWASP ZAP
- Syft vs Tenable Nessus
- Syft vs Transmit Security
- Syft vs TrustArc
- Syft vs Varonis Data Security Platform
- Syft vs VMware Carbon Black
