Alternativen zu

Snyk

Hosted security platform that scans dependencies, container images, code and infrastructure as code for known vulnerabilities. Ein geschlossenes Produkt von Snyk.

Im Vergleich

8 Open-Source-Alternativen zu Snyk
ToolErsatzgradSterneLizenzBedingungenSelbst hostbarSpracheNeuestes ReleaseLetzter Push
TrivyTeilweise38kApache-2.0Open SourceNeinGov0.75.02026-10-06
GrypeTeilweise13kApache-2.0Open SourceNeinGov0.120.02026-10-05
OSV-ScannerTeilweise11kApache-2.0Open SourceNeinGov2.6.02026-10-05
ClairTeilweise11kApache-2.0Open SourceNeinGov4.9.02026-09-30
CheckovTeilweise9.1kApache-2.0Open SourceNeinPython3.3.232026-10-06
Dependency-CheckTeilweise7.7kApache-2.0Open SourceNeinJavav13.0.02026-10-05
Dependency-TrackTeilweise4.3kApache-2.0Open SourceJaJava5.1.22026-10-06
KICSTeilweise2.7kApache-2.0Open SourceNeinOpen Policy Agentv2.2.02026-10-06

Alle Alternativen

Sprache
Hosting

8 Alternativen

TrivyTeilweise

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Scans dependencies, container images, infrastructure as code and secrets from the CLI or CI; no hosted dashboard or fix pull requests.

Sprache
Go
Sterne
38k
Neuestes Release
v0.75.0
Letzter Push
2026-10-06
GrypeTeilweise

A vulnerability scanner for container images and filesystems

Dependency and container image scanning, from an image, a directory or an SBOM; no code or IaC scanning.

Sprache
Go
Sterne
13k
Neuestes Release
v0.120.0
Letzter Push
2026-10-05
OSV-ScannerTeilweise

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Dependency and container image scanning against OSV.dev, with guided remediation for npm and Maven.

Sprache
Go
Sterne
11k
Neuestes Release
v2.6.0
Letzter Push
2026-10-05
ClairTeilweise

Vulnerability Static Analysis for Containers

Container image scanning as a service behind a registry; no code or dependency scanning.

Sprache
Go
Sterne
11k
Neuestes Release
v4.9.0
Letzter Push
2026-09-30
CheckovTeilweise

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Only the infrastructure as code checks, for Terraform, CloudFormation, Kubernetes and more.

Sprache
Python
Sterne
9.1k
Neuestes Release
3.3.23
Letzter Push
2026-10-06
Dependency-CheckTeilweise

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Dependency scanning against the NVD, with Maven, Gradle and Ant plugins; no container image scanning.

Sprache
Java
Sterne
7.7k
Neuestes Release
v13.0.0
Letzter Push
2026-10-05
Dependency-TrackTeilweise

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Continuous monitoring of dependencies from SBOMs with policies, without fix pull requests.

Sprache
Java
Sterne
4.3k
Neuestes Release
5.1.2
Letzter Push
2026-10-06
KICSTeilweise

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Only the infrastructure as code checks, with queries for Terraform, Kubernetes, Docker and more.

Sterne
2.7k
Neuestes Release
v2.2.0
Letzter Push
2026-10-06

Direkt verglichen

Über Snyk

Anbieter
Snyk

Website von Snyk ↗