alternatives to

Snyk

Hosted security platform that scans dependencies, container images, code and infrastructure as code for known vulnerabilities. A closed product from Snyk.

Side by side

8 open source alternatives to Snyk
ToolFitStarsLicenceTermsSelf-hostedLanguageLatestLast push
TrivyPartial38kApache-2.0Open sourceNoGov0.75.02026-10-06
GrypePartial13kApache-2.0Open sourceNoGov0.120.02026-10-05
OSV-ScannerPartial11kApache-2.0Open sourceNoGov2.6.02026-10-05
ClairPartial11kApache-2.0Open sourceNoGov4.9.02026-09-30
CheckovPartial9.1kApache-2.0Open sourceNoPython3.3.232026-10-06
Dependency-CheckPartial7.7kApache-2.0Open sourceNoJavav13.0.02026-10-05
Dependency-TrackPartial4.3kApache-2.0Open sourceYesJava5.1.22026-10-06
KICSPartial2.7kApache-2.0Open sourceNoOpen Policy Agentv2.2.02026-10-06

Every alternative

Language
Hosting

8 alternatives

TrivyPartial

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Scans dependencies, container images, infrastructure as code and secrets from the CLI or CI; no hosted dashboard or fix pull requests.

Language
Go
Licence
Apache-2.0
Stars
38k
Latest
v0.75.0
Last push
2026-10-06
GrypePartial

A vulnerability scanner for container images and filesystems

Dependency and container image scanning, from an image, a directory or an SBOM; no code or IaC scanning.

Language
Go
Licence
Apache-2.0
Stars
13k
Latest
v0.120.0
Last push
2026-10-05
OSV-ScannerPartial

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Dependency and container image scanning against OSV.dev, with guided remediation for npm and Maven.

Language
Go
Licence
Apache-2.0
Stars
11k
Latest
v2.6.0
Last push
2026-10-05
ClairPartial

Vulnerability Static Analysis for Containers

Container image scanning as a service behind a registry; no code or dependency scanning.

Language
Go
Licence
Apache-2.0
Stars
11k
Latest
v4.9.0
Last push
2026-09-30
CheckovPartial

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Only the infrastructure as code checks, for Terraform, CloudFormation, Kubernetes and more.

Language
Python
Licence
Apache-2.0
Stars
9.1k
Latest
3.3.23
Last push
2026-10-06
Dependency-CheckPartial

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Dependency scanning against the NVD, with Maven, Gradle and Ant plugins; no container image scanning.

Language
Java
Licence
Apache-2.0
Stars
7.7k
Latest
v13.0.0
Last push
2026-10-05
Dependency-TrackPartial

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Continuous monitoring of dependencies from SBOMs with policies, without fix pull requests.

Language
Java
Licence
Apache-2.0
Stars
4.3k
Latest
5.1.2
Last push
2026-10-06
KICSPartial

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Only the infrastructure as code checks, with queries for Terraform, Kubernetes, Docker and more.

Licence
Apache-2.0
Stars
2.7k
Latest
v2.2.0
Last push
2026-10-06

Head to head

About Snyk

Vendor
Snyk

Snyk website ↗