101% more reported CVEs per day in 2026 than last year.

Alternatives

Syft and Grype alternatives

Syft and Grype are the free standard for generating and matching SBOMs. Teams look at alternatives when they need a different format or ecosystem, an SBOM of what the build actually used, or monitoring they do not have to run.

Updated

We build CRACI, so weigh that in; we describe every option from its own documentation and say when another tool fits better.

Why teams look beyond Syft and Grype

The Syft and Grype homepage
anchore.com

Syft is Anchore's free, Apache-2.0 generator for container images and filesystems. It recognizes dozens of package types, writes CycloneDX, SPDX and Syft JSON, and can create signed in-toto SBOM attestations. Grype, its companion, matches the SBOM against vulnerabilities.

Teams look elsewhere when their situation changes:

  • Settings. Catalogers are chosen by scan type, so on an installed express checkout one flag decides whether npm packages appear in the result at all.
  • Format and ecosystem. Some teams want a generator from the CycloneDX community, SPDX from a build output, or a tool made for one package manager.
  • Evidence. The SBOM describes the files scanned, not what the build fetched.
  • Monitoring. Watching what shipped means storing SBOMs and rerunning Grype yourself.

What to look for

  • Whether the SBOM comes from files on disk or from what the build fetched.
  • Transitive dependencies, and whether the tool says when its record is incomplete.
  • Monitoring after release, not only a scan when you run it.
  • Formats: CycloneDX, SPDX and VEX.
  • What else you need scanned: images you did not build, IaC, secrets, clusters.

The options

The first six are SBOM generators. The rest add vulnerability matching, monitoring or a wider platform around the SBOM.

1. CRACI (our product)

The CRACI homepage
craci.com

CRACI records the SBOM while your GitHub Actions build runs, instead of scanning files afterwards. A package-aware proxy records every package the job fetched, including packages restored from CI caches, and each SBOM, in CycloneDX or SPDX, states its completeness per job and per cache. CRACI keeps re-evaluating monitored SBOMs as new vulnerabilities appear, policy gates can block a build on findings, and the API returns SBOMs, network traces and provenance.

Best for: the SBOM and dependency vulnerabilities of the software you build on GitHub Actions.

Consider if: you do not need infrastructure as code, secret, cluster or VM image scanning, which CRACI does not do, and your builds run on GitHub Actions on Linux.

Build-time SBOM generation

2. cdxgen (open source)

The cdxgen homepage
github.com

cdxgen is an OWASP CycloneDX project that creates CycloneDX BOMs from source and container images, under Apache-2.0. For Node.js it parses lock files first, including development dependencies, and also analyzes the code for imports. You can set the project type with -t to limit what it looks for.

Best for: teams standardized on CycloneDX that want a generator from the format's own community.

Consider if: you can work with what the files declare: like the other scanners, it can only report what is in front of it.

Syft, Trivy and cdxgen SBOMs

3. Microsoft SBOM Tool (open source)

The Microsoft SBOM Tool homepage
github.com

The Microsoft SBOM Tool is an MIT-licensed generator that writes SPDX 2.2, or SPDX 3.0 on request, and can validate an SBOM against the SPDX specification. It expects a build drop folder, a package name, a version and a supplier on the command line, which makes it a post-build step, and it runs in GitHub Actions and Azure Pipelines.

Best for: teams that want SPDX for a build output they already package.

Consider if: you point it at a build drop: pointed at a repository as committed, it has almost nothing to describe.

CRACI vs a DIY SBOM stack

4. CycloneDX tools and build plugins (open source)

The CycloneDX project maintains generators for single ecosystems, listed in its Tool Center: plugins for Maven, Gradle and Apache Ant, and tools for npm, Yarn, Python, .NET, Go modules, Rust Cargo, PHP Composer, Ruby Gems, Erlang and Elixir, and Conan. The separate CycloneDX CLI, under Apache 2.0, does not generate SBOMs: it converts, merges, diffs, validates and signs them.

Best for: a project in one ecosystem that wants a generator made for that ecosystem.

Consider if: you can run one tool per ecosystem in a codebase that mixes languages.

CycloneDX vs SPDX

5. Tern (open source)

Tern is a software composition analysis tool and Python library that generates an SBOM for container images and Dockerfiles, under BSD-2-Clause. It gives a layer-by-layer view of what is inside a container, from the package metadata in each layer, and writes SPDX tag-value, SPDX JSON and CycloneDX JSON, among other formats.

Best for: seeing which image layer brought in which package.

Consider if: your SBOM needs are about container images rather than source repositories.

Docker image SBOMs

6. Amazon Inspector SBOM Generator

Sbomgen is the generator behind Amazon Inspector's own image, Lambda and EC2 scanning, offered as a standalone Linux binary. It reads package metadata from container images, directories, archives, mounted volumes and compiled Go and Rust binaries, and writes CycloneDX. It can send the SBOM to the Amazon Inspector Scan API for vulnerability findings, which needs an AWS account.

Best for: teams whose workloads already run on AWS.

Consider if: you run it on Linux, the only platform it supports.

SBOM tools compared

7. Trivy (open source)

The Trivy homepage
trivy.dev

A free scanner under Apache-2.0 from Aqua Security. It scans container images, filesystems, repositories, VM images and Kubernetes for vulnerabilities, IaC misconfigurations, secrets and licenses, and writes CycloneDX or SPDX SBOMs. For a repository it reads lock files; for an image, installed package metadata.

Best for: teams on a tight budget, or that want one scanner in any CI.

Consider if: you can build the rest yourself: monitoring means rescanning on your own schedule.

CRACI vs Trivy

8. Anchore Enterprise

The Anchore homepage
anchore.com

Anchore Enterprise builds on Anchore's open-source Syft and Grype. It generates SBOMs from container images, source and filesystems, imports SBOMs created elsewhere, rescans stored SBOMs without the original artifact, and enforces policy packs for FedRAMP, NIST, CIS, PCI DSS and CMMC. It deploys on Kubernetes, Docker Compose or air-gapped. Pricing is by quote.

Best for: container fleets across several CI systems, and government or air-gapped environments.

CRACI vs Anchore

9. Dependency-Track (open source)

The Dependency-Track homepage
dependencytrack.org

OWASP Dependency-Track is a free, Apache 2.0 platform that tracks components across every version of every application in your portfolio. It pulls vulnerability data from sources including the NVD and GitHub Advisories, has a policy engine for security, license and operational rules, and consumes and produces CycloneDX VEX.

Best for: teams that want a transparent, self-hosted SBOM platform without a license fee.

Consider if: you are ready to operate it and to feed it; it analyzes the SBOMs you upload and does not generate them.

CRACI for Dependency-Track users

10. Aikido

The Aikido homepage
aikido.dev

A broad AppSec suite. Every plan lists SCA, SAST, secrets, IaC, cloud posture, container scanning, DAST, license scanning and SBOM generation. Its SCA uses function-level reachability, AutoFix opens pull requests, and it can block pull requests with critical findings. There is a free Developer plan, and paid plans start at $350 per month (as of September 2026).

Best for: smaller teams that want one tool and one dashboard for most scanning needs.

CRACI vs Aikido

11. GitHub Advanced Security

The GitHub Advanced Security homepage
github.com

Two paid products on top of GitHub's platform features. Secret Protection covers secret scanning and push protection; Code Security covers CodeQL code scanning, Copilot Autofix and dependency review. They build on the dependency graph and Dependabot, which all GitHub plans include, and the graph exports as an SPDX SBOM. Secret Protection is $19 and Code Security $30 per active committer per month, on Team or Enterprise (as of September 2026).

Best for: teams whose code and workflows already live on GitHub and want fewer vendors.

CRACI vs GitHub Advanced Security

Side by side

SBOM generators as of September 2026.
Capability CRACI Syft Trivy cdxgen Microsoft SBOM Tool GitHub export Amazon Inspector Sbomgen
Where the component list comes from Recorded build traffic Catalogers read files and images Lock files or installed packages Source and container images A build drop folder Manifests and lock files Files in images, directories, archives and binaries
Formats CycloneDX, SPDX CycloneDX, SPDX, Syft JSON CycloneDX, SPDX CycloneDX SPDX SPDX CycloneDX
Records what the build fetched Including CI caches Dependency submission
Works without running the build
Signed attestation or provenance No signed provenance in-toto SBOM attestation With Cosign Not stated Not stated Artifact attestations Not stated
Vulnerability matching Monitored SBOMs Pair with Grype Not stated Not stated Dependabot alerts Inspector Scan API
Egress policy for the build Fails closed
Runs in any CI GitHub Actions today; GitLab CI and Jenkins on the roadmap GitHub repositories Linux only
Price Pay per build minute, no monthly fee Free, Apache-2.0 Free, Apache-2.0 Free, Apache-2.0 Free, MIT Included with GitHub Free download
  • Included
  • Partly
  • Not included
  • On the roadmap

"Not stated" means we could not confirm it in the vendor's public pages.

When to stay with Syft and Grype

  • You scan images you did not build.
  • You rely on Grype's VEX filtering or severity gates in CI.
  • You want a free generator that runs anywhere.
  • You can combine: keep Syft and Grype for images you did not build.

Read more about build-time SBOM generation, the SBOM tools compared and what open-source SBOM generators miss.

Syft and Grype alternatives FAQ

Short answers to the questions teams ask when they compare

What is the best open-source SBOM generator?

It depends on what you point it at. Syft and Trivy are free Apache-2.0 generators for container images and filesystems. cdxgen writes CycloneDX from source and images, the CycloneDX build plugins cover one ecosystem each, the Microsoft SBOM Tool writes SPDX for a build output folder, and Tern shows an image layer by layer. All of them read files. CRACI, a paid product, records the SBOM from the build itself.

How much does Syft cost?

Nothing. Syft and Grype are free and open source under Apache-2.0. Anchore sells Anchore Enterprise, a separate commercial platform built on them, and prices it by quote (as of September 2026).

How can I generate an SBOM using Syft?

Run syft with a target and an output format, for example syft my-image:latest -o spdx-json=sbom.spdx.json for an image, or syft ./my-project -o cyclonedx-json=sbom.cdx.json for a directory. syft cataloger list shows which catalogers run for that scan type.

What is the difference between Syft and Grype?

Syft generates the SBOM. Grype is the vulnerability scanner: it scans container images, filesystems and SBOMs, prioritizes with EPSS and KEV data, and supports OpenVEX to filter results. Both come from Anchore under Apache-2.0, and teams usually run them together.

Can CRACI replace Syft and Grype?

For the software you build on GitHub Actions, yes. CRACI records the SBOM while the build runs, with a completeness state per job and per cache, and keeps re-evaluating monitored SBOMs as new vulnerabilities appear. For images you did not build, keep a scanner such as Syft and Grype.

Record one build and compare

Run one GitHub Actions job on CRACI and set its recorded SBOM next to the one your scanner produces.

Book a demo