compare
Grype vs KICS
The same facts for both, read from GitHub every night, and the relation a person reviewed.
| Fact | Grype | KICS |
|---|---|---|
| Language | Go | Open Policy Agent |
| Licence | Apache-2.0 | Apache-2.0 |
| Stars | 13k | 2.7k |
| Latest | v0.120.0 | v2.2.0 |
| Last push | 2026-10-05 | 2026-10-06 |
| Release cadence | about 16 days between releases | about 52 days between releases |
| Active contributors | 20 commit authors on the default branch in the last 90 days | 8 commit authors on the default branch in the last 90 days |
| Flags | none | none |
How they relate
Both replace Snyk. Alternatives to Snyk →
PartialGrypeDependency and container image scanning, from an image, a directory or an SBOM; no code or IaC scanning.
PartialKICSOnly the infrastructure as code checks, with queries for Terraform, Kubernetes, Docker and more.
Grype
- v0.120.02026-10-02Mark SLES as a comprehensive distro PR [#3732 @willmurphyscode]
- v0.119.02026-09-17Expose distro-fixed dropped matches via ignoredMatches so --show-suppressed can surface them Issue [#3450] PR [#3705 @p…
- v0.118.02026-08-27apk matcher does alias aware aggregation PR [#3634 @crosleyzack]
- v0.117.02026-08-10Include vulnerable ranges in CycloneDX output format Issue [#3512] PR [#3519 @somaz94]
- v0.116.12026-07-28Ensure channel parsing is consistent PR [#3603 @wagoodman]
KICS
- v2.2.02026-09-17docs(release): update queries catalog, index and dockerfile for upcoming release
- v2.1.212026-07-30fix(query): fix EFS Volume With Disabled Transit Encryption queries for multiple volumes cases
- v2.1.202026-03-03feat(query): implements "Beta - Azure Container Registry With Broad Permissions"
- v2.1.192026-01-07fix(Bicep): Remove existing resources from bicep payload
- v2.1.182025-12-18feat(query): implements "Beta - Activity Log Alert For Create Policy Assignment Not Configured"
Grype
unsigned The latest release, v0.120.0, carries no signature GitHub could verify.
Loading the security report
KICS
✓ signed The latest release, v2.2.0, carries a signature GitHub verified.
Loading the security report