vergleichen
Checkov vs Grype
Dieselben Fakten für beide, jede Nacht von GitHub gelesen, dazu die von Hand geprüfte Beziehung.
| Fakt | Checkov | Grype |
|---|---|---|
| Sprache | Python | Go |
| Lizenz | Apache-2.0 | Apache-2.0 |
| Sterne | 9.1k | 13k |
| Neuestes Release | 3.3.23 | v0.120.0 |
| Letzter Push | 2026-10-06 | 2026-10-05 |
| Release-Rhythmus | etwa 6 Tage zwischen Releases | etwa 16 Tage zwischen Releases |
| Aktive Mitwirkende | nicht gezählt | 20 Commit-Autoren auf dem Standard-Branch in den letzten 90 Tagen |
| Hinweise | keine | keine |
Wie sie zusammenhängen
Beide ersetzen Snyk. Alternativen zu Snyk →
TeilweiseCheckovOnly the infrastructure as code checks, for Terraform, CloudFormation, Kubernetes and more.
TeilweiseGrypeDependency and container image scanning, from an image, a directory or an SBOM; no code or IaC scanning.
Checkov
- 3.3.232026-10-05sca: apply --skip-path regex and hidden-dir filtering to sca_package - #7712
- 3.3.212026-09-30terraform_json: handle HCL JSON array and single-dict block formats in parser - #7707
- 3.3.202026-09-27terraform_plan: skip resources being removed from state ('forget' action) - #7676
- 3.3.192026-09-17terraform: add CKV_AWS_394 for unconstrained aws_availability_zones data source - #7658
- 3.3.172026-09-10general: honour scope.provider for platform-downloaded custom po… - #7677
Grype
- v0.120.02026-10-02Mark SLES as a comprehensive distro PR [#3732 @willmurphyscode]
- v0.119.02026-09-17Expose distro-fixed dropped matches via ignoredMatches so --show-suppressed can surface them Issue [#3450] PR [#3705 @p…
- v0.118.02026-08-27apk matcher does alias aware aggregation PR [#3634 @crosleyzack]
- v0.117.02026-08-10Include vulnerable ranges in CycloneDX output format Issue [#3512] PR [#3519 @somaz94]
- v0.116.12026-07-28Ensure channel parsing is consistent PR [#3603 @wagoodman]
Checkov
unsigniert Das neueste Release, 3.3.23, trägt keine Signatur, die GitHub prüfen könnte.
Der Sicherheitsbericht wird geladen
Grype
unsigniert Das neueste Release, v0.120.0, trägt keine Signatur, die GitHub prüfen könnte.
Der Sicherheitsbericht wird geladen