Grypevs
Trivy


Trivy: Broader scanning in one tool, including misconfiguration and secrets
Overview
Grype is an open-source vulnerability scanner for container images and filesystems from Anchore. It pairs with Syft, Anchore’s software bill of materials generator: Syft catalogues what is in an image, Grype matches that inventory against vulnerability data. That separation is the design point. An SBOM produced once can be scanned repeatedly as new vulnerabilities are published, without re-analysing the image — which matters when the question is not "was this safe at build time" but "is it safe today".
The honest half
Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Grype.
Cross-shopped
Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.


Trivy: Broader scanning in one tool, including misconfiguration and secrets


Snyk: Commercial scanning with triage, fix pull requests and reporting
Pricing
Taken from the vendor's own pricing page. Prices move, so check before you buy.
Grype
Free
Capabilities
Image and filesystem scanning
Containers, directories and archives
SBOM-driven
Scans a Syft SBOM directly, so inventory and matching are separate steps
Wide ecosystem coverage
OS packages plus most major language dependency formats
Pipeline friendly
Single binary with exit codes and machine-readable output
Answered, with sources
Each answer names the page it came from, so you can check it rather than take our word for it.
Yes, open source from Anchore. Anchore Enterprise is the paid platform around it.
Syft generates the software bill of materials; Grype matches that inventory against vulnerability data. They are designed to be used together.
They cover similar ground. Trivy is broader out of the box, including misconfiguration and secret scanning; Grype pairs more cleanly with an SBOM-first workflow.
Keep looking
The world's most-loved password manager
The world's #1 rated antivirus
Powerful protection against evolving threats
Simplify online life with LastPass password manager
Developer-first security platform
Open source password management for everyone
Secure, fast & private web browser with adblocker
Drop-in user authentication and management for developers
Stop breaches with AI-native cybersecurity
Complete protection for your digital life
Privacy-first VPN with one flat price and no email required to sign up
Enterprise AI governance and data compliance platform.
Long-standing VPN service with a large server network and flexible multi-year plans
Secure email that protects your privacy
Secure, green and ad-free. Email to feel good about.
Runtime identity security at agentic scale
Secrets management for humans and AI agents
Customer identity and access management platform for SaaS applications
Softwr does not host reviews and shows no star rating for Grype, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.
What people switch to, and what they give up
Every tier, and where the cost actually lands
Put it head to head with anything we hold
Its rating, and an embed for your own site
Open-source authentication and two-factor portal for reverse proxies
Headless identity and user management API
Open-source identity provider with flexible authentication flows
Open-source vulnerability and misconfiguration scanner
Secrets management for humans and AI agents
Security and AI agent governance for code and supply chain
Unified security platform automating vulnerability detection and fixing across development