101% more reported CVEs per day in 2026 than last year.

Alternatives

Trivy alternatives

Trivy is one free binary for many security checks. Teams look at alternatives when they want a dedicated tool for one job, an SBOM of what the build actually used, monitoring after release, or a platform around the scans.

Updated

We build CRACI, so weigh that in; we describe every option from its own documentation and say when another tool fits better.

Why teams look beyond Trivy

The Trivy homepage
trivy.dev

Trivy, from Aqua Security, is a versatile Apache-2.0 scanner for images, filesystems, repositories, VM images and Kubernetes. It finds vulnerabilities, IaC misconfigurations, secrets and licenses, and writes CycloneDX or SPDX SBOMs.

Teams look elsewhere when their situation changes:

  • The March 2026 supply chain compromise. Aqua Security's advisory (CVE-2026-33634) describes a malicious Trivy v0.69.4 release and poisoned trivy-action and setup-trivy tags on March 19, 2026, followed by malicious Docker Hub images on March 22. The injected code stole credentials from CI runners. Aqua published safe versions and recommends pinning actions to full commit SHAs.
  • Breadth over depth. One binary covers many jobs. Teams that need more in one area, such as container images or infrastructure as code, often move that job to a dedicated tool.
  • Inputs. For a repository Trivy reads lock files, so a project without one gives it nothing to read.
  • Evidence. Its SBOM describes the files it scanned, not what the build fetched.
  • Monitoring. It scans when you run it; watching what shipped means rescanning on your own schedule.

Every scanner your pipeline downloads and runs is itself part of your software supply chain, running next to the job's secrets. On CRACI, the runner records the SBOM, so there is no scanner step to download for the software you build. The runner's egress policy can limit which hosts any step in the job reaches, and each job's network trace is recorded. Pinning actions to commit SHAs, as Aqua recommends, applies on CRACI too.

What to look for

  • Which Trivy job you are replacing: image scanning, IaC, secrets or SBOMs.
  • Whether the SBOM comes from files on disk or from what the build fetched.
  • Transitive dependencies, and whether the tool says when its record is incomplete.
  • Monitoring after release, not only a scan when you run it.
  • Formats: CycloneDX, SPDX and VEX.

The options

Grype, Docker Scout, Snyk Container and Clair scan container images. Checkov and KICS scan infrastructure as code, and Gitleaks finds secrets. CRACI, Anchore Enterprise, Aikido, Dependency-Track and GitHub Advanced Security cover SBOMs and dependency vulnerabilities in different ways.

1. CRACI (our product)

The CRACI homepage
craci.com

CRACI records the SBOM while your GitHub Actions build runs, instead of scanning files afterwards. A package-aware proxy records every package the job fetched, including packages restored from CI caches, and each SBOM, in CycloneDX or SPDX, states its completeness per job and per cache. CRACI keeps re-evaluating monitored SBOMs as new vulnerabilities appear, policy gates can block a build on findings, and the API returns SBOMs, network traces and provenance.

Best for: the SBOM and dependency vulnerabilities of the software you build on GitHub Actions.

Consider if: you do not need infrastructure as code, secret, cluster or VM image scanning, which CRACI does not do, and your builds run on GitHub Actions on Linux.

Build-time SBOM generation

2. Syft and Grype (open source)

The Syft and Grype homepage
anchore.com

Syft is Anchore's free, Apache-2.0 generator for container images and filesystems. It recognizes dozens of package types, writes CycloneDX, SPDX and Syft JSON, and can create signed in-toto SBOM attestations. Grype, its companion, matches the SBOM against vulnerabilities.

Best for: images, and any pipeline that needs a free generator.

Consider if: you can check the scan settings: catalogers are chosen by scan type, so one flag can decide whether npm packages appear at all.

CRACI vs Syft and Grype

3. Docker Scout

Docker Scout analyzes container images: it compiles an inventory of their components, an SBOM, and matches it against a continuously updated vulnerability database. You use it from Docker Hub, the Docker CLI and the Docker Scout Dashboard. It integrates with GitHub Actions, GitLab, Azure DevOps Pipelines, CircleCI and Jenkins, and with OCI registries such as Amazon ECR, Azure Container Registry, JFrog Artifactory, Harbor and Sonatype Nexus. As of September 2026, the free Docker Personal plan includes 1 Scout-enabled repository and Pro includes 2; Team, at $15 per user per month billed annually, and Business include unlimited repositories.

Best for: teams that already build and store images with Docker's tools.

Consider if: you need more than two repositories analyzed, which takes a Team or Business plan.

4. Snyk Container

The Snyk homepage
snyk.io

Snyk Container scans container images and the open-source dependencies inside them, recommends base images with fewer vulnerabilities, and monitors Kubernetes workloads. It connects to registries including Docker Hub, Amazon ECR, Azure ACR, Google GCR, Artifactory, Harbor and Red Hat Quay, and prioritizes findings by exploit maturity and workload configuration. As of September 2026, Snyk has a Free plan, Team from $25 per month, and an Enterprise plan.

Best for: developers who want base image upgrade advice next to Snyk's code and dependency scanning.

CRACI vs Snyk

5. Clair (open source)

Clair, from the Quay project, is an Apache 2.0 service for static analysis of vulnerabilities in container images. Its indexer fetches image layers, its matcher checks the index against vulnerability data, and its notifier alerts you when a new vulnerability affects an image it has already indexed. It matches operating system packages for Ubuntu, Debian, RHEL, SUSE, Oracle, Alpine, Amazon Linux and VMware Photon, plus Python packages.

Best for: registries and platforms that need an image scanning service behind an API, as in Quay.

Consider if: you are ready to run a service rather than a CLI, and its language coverage fits your images.

6. Checkov (open source)

Checkov, maintained by Prisma Cloud from Palo Alto Networks, scans infrastructure as code: Terraform and Terraform plans, OpenTofu, CloudFormation, AWS SAM, Kubernetes, Helm, Kustomize, Dockerfiles, Serverless, Bicep, ARM templates and OpenAPI. It also scans open-source packages and container images for CVEs and finds secrets with regex, keyword and entropy checks. It is open source under Apache-2.0.

Best for: replacing Trivy's misconfiguration scanning for infrastructure as code.

7. KICS (open source)

KICS, from Checkmarx, finds security issues in infrastructure as code. It covers Terraform, Kubernetes, Docker, CloudFormation, Ansible, Helm, Pulumi and more, and is open source under Apache-2.0.

Best for: an open-source IaC scanner that also covers Ansible and Pulumi.

8. Gitleaks (open source)

Gitleaks detects passwords, API keys and tokens in Git repositories and files. It is open source under MIT.

Best for: replacing Trivy's secret scanning with a dedicated tool.

9. Anchore Enterprise

The Anchore homepage
anchore.com

Anchore Enterprise builds on Anchore's open-source Syft and Grype. It generates SBOMs from container images, source and filesystems, imports SBOMs created elsewhere, rescans stored SBOMs without the original artifact, and enforces policy packs for FedRAMP, NIST, CIS, PCI DSS and CMMC. It deploys on Kubernetes, Docker Compose or air-gapped. Pricing is by quote.

Best for: container fleets across several CI systems, and government or air-gapped environments.

CRACI vs Anchore

10. Aikido

The Aikido homepage
aikido.dev

A broad AppSec suite. Every plan lists SCA, SAST, secrets, IaC, cloud posture, container scanning, DAST, license scanning and SBOM generation. Its SCA uses function-level reachability, AutoFix opens pull requests, and it can block pull requests with critical findings. There is a free Developer plan, and paid plans start at $350 per month (as of September 2026).

Best for: smaller teams that want one tool and one dashboard for most scanning needs.

CRACI vs Aikido

11. Dependency-Track (open source)

The Dependency-Track homepage
dependencytrack.org

OWASP Dependency-Track is a free, Apache 2.0 platform that tracks components across every version of every application in your portfolio. It pulls vulnerability data from sources including the NVD and GitHub Advisories, has a policy engine for security, license and operational rules, and consumes and produces CycloneDX VEX.

Best for: teams that want a transparent, self-hosted SBOM platform without a license fee.

Consider if: you are ready to operate it and to feed it; it analyzes the SBOMs you upload and does not generate them.

CRACI for Dependency-Track users

12. GitHub Advanced Security

The GitHub Advanced Security homepage
github.com

Two paid products on top of GitHub's platform features. Secret Protection covers secret scanning and push protection; Code Security covers CodeQL code scanning, Copilot Autofix and dependency review. They build on the dependency graph and Dependabot, which all GitHub plans include, and the graph exports as an SPDX SBOM. Secret Protection is $19 and Code Security $30 per active committer per month, on Team or Enterprise (as of September 2026).

Best for: teams whose code and workflows already live on GitHub and want fewer vendors.

CRACI vs GitHub Advanced Security

Grype vs Trivy

Both are free, open-source scanners under Apache-2.0, and both scan container images and filesystems. The difference is scope:

  • Grype focuses on vulnerabilities. It scans Docker, OCI and Singularity images, filesystems and SBOMs, covers OS packages and languages including Java, JavaScript, Python, .NET, Go, PHP, Ruby and Rust, prioritizes with EPSS and KEV data, and filters results with OpenVEX. SBOM generation is Syft's job.
  • Trivy does more in one binary. Beyond vulnerabilities it finds IaC misconfigurations, secrets and licenses, scans repositories, virtual machine images and Kubernetes, and writes CycloneDX or SPDX SBOMs itself.

Choose Grype, with Syft, when you want a focused image and SBOM scanner. Choose Trivy when one tool for many checks matters more. Both read the files in front of them, so both depend on lock files or installed packages being present.

Side by side

SBOM generators as of September 2026.
Capability CRACI Syft Trivy cdxgen Microsoft SBOM Tool GitHub export Amazon Inspector Sbomgen
Where the component list comes from Recorded build traffic Catalogers read files and images Lock files or installed packages Source and container images A build drop folder Manifests and lock files Files in images, directories, archives and binaries
Formats CycloneDX, SPDX CycloneDX, SPDX, Syft JSON CycloneDX, SPDX CycloneDX SPDX SPDX CycloneDX
Records what the build fetched Including CI caches Dependency submission
Works without running the build
Signed attestation or provenance No signed provenance in-toto SBOM attestation With Cosign Not stated Not stated Artifact attestations Not stated
Vulnerability matching Monitored SBOMs Pair with Grype Not stated Not stated Dependabot alerts Inspector Scan API
Egress policy for the build Fails closed
Runs in any CI GitHub Actions today; GitLab CI and Jenkins on the roadmap GitHub repositories Linux only
Price Pay per build minute, no monthly fee Free, Apache-2.0 Free, Apache-2.0 Free, Apache-2.0 Free, MIT Included with GitHub Free download
  • Included
  • Partly
  • Not included
  • On the roadmap

"Not stated" means we could not confirm it in the vendor's public pages.

When to stay with Trivy

  • You scan infrastructure as code, Kubernetes clusters, VM images, secrets or misconfigurations.
  • You scan images or software you did not build.
  • You want one free binary that runs in any CI.
  • You can combine: keep Trivy for what CRACI does not scan.

Read more in CRACI vs Trivy, about build-time SBOM generation and in the SBOM tools compared.

Trivy alternatives FAQ

Short answers to the questions teams ask when they compare

What is the best alternative to Trivy?

It depends on which Trivy job you are replacing. For container images, Grype is the closest open-source match, and Docker Scout, Snyk Container and Clair are other options. For infrastructure as code, Checkov and KICS. For secrets, Gitleaks. For the SBOM and dependency vulnerabilities of software you build on GitHub Actions, CRACI records the SBOM from the build and keeps tracking it. No single tool replaces all of Trivy.

Is Trivy free?

Yes. Trivy is open source under Apache-2.0 and maintained by Aqua Security. Grype, Clair, Checkov and KICS are free under Apache-2.0 too, and Gitleaks under MIT.

Grype vs Trivy: which is better?

Neither in general. Grype focuses on vulnerabilities in container images, filesystems and SBOMs, with EPSS and KEV data and OpenVEX filtering, and pairs with Syft for SBOMs. Trivy covers more in one binary: infrastructure as code, secrets, licenses, virtual machine images and Kubernetes as well. Pick Grype for focused vulnerability scanning and Trivy for one tool across many checks.

Is Trivy still safe to use after the March 2026 compromise?

Aqua Security's advisory (CVE-2026-33634) describes a malicious Trivy v0.69.4 release and poisoned trivy-action and setup-trivy tags on March 19, 2026, and malicious Docker Hub images on March 22. Aqua lists safe versions and recommends rotating secrets that may have been exposed and pinning GitHub Actions to full commit SHAs. Check the advisory for the versions you run.

Does Trivy scan infrastructure as code?

Yes. Trivy finds misconfigurations in infrastructure as code alongside vulnerabilities, secrets and licenses. If you want a dedicated IaC scanner instead, Checkov and KICS are open-source options.

Can CRACI replace Trivy?

For the SBOM and dependency vulnerabilities of the software you build on GitHub Actions, yes: CRACI records the SBOM while the build runs and keeps re-evaluating it against vulnerability data. CRACI does not scan infrastructure as code, Kubernetes clusters, virtual machine images, secrets, misconfigurations or images you did not build. Keep Trivy, or another scanner, for those.

Record one build and compare

Run one GitHub Actions job on CRACI and set its recorded SBOM next to the one your scanner produces.

Book a demo