代替ツール

Snyk

Hosted security platform that scans dependencies, container images, code and infrastructure as code for known vulnerabilities. Snykのクローズドな製品です。

比較表

Snykのオープンソース代替8選
ツール置き換えの度合いスターライセンス利用条件セルフホスト言語最新リリース最終プッシュ
Trivy部分的38kApache-2.0オープンソース不可Gov0.75.02026-10-06
Grype部分的13kApache-2.0オープンソース不可Gov0.120.02026-10-05
OSV-Scanner部分的11kApache-2.0オープンソース不可Gov2.6.02026-10-05
Clair部分的11kApache-2.0オープンソース不可Gov4.9.02026-09-30
Checkov部分的9.1kApache-2.0オープンソース不可Python3.3.232026-10-06
Dependency-Check部分的7.7kApache-2.0オープンソース不可Javav13.0.02026-10-05
Dependency-Track部分的4.3kApache-2.0オープンソース可Java5.1.22026-10-06
KICS部分的2.7kApache-2.0オープンソース不可Open Policy Agentv2.2.02026-10-06

すべての代替ツール

言語
ホスティング

代替8件

Trivy部分的

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Scans dependencies, container images, infrastructure as code and secrets from the CLI or CI; no hosted dashboard or fix pull requests.

言語
Go
ライセンス
Apache-2.0
スター
38k
最新リリース
v0.75.0
最終プッシュ
2026-10-06
Grype部分的

A vulnerability scanner for container images and filesystems

Dependency and container image scanning, from an image, a directory or an SBOM; no code or IaC scanning.

言語
Go
ライセンス
Apache-2.0
スター
13k
最新リリース
v0.120.0
最終プッシュ
2026-10-05
OSV-Scanner部分的

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Dependency and container image scanning against OSV.dev, with guided remediation for npm and Maven.

言語
Go
ライセンス
Apache-2.0
スター
11k
最新リリース
v2.6.0
最終プッシュ
2026-10-05
Clair部分的

Vulnerability Static Analysis for Containers

Container image scanning as a service behind a registry; no code or dependency scanning.

言語
Go
ライセンス
Apache-2.0
スター
11k
最新リリース
v4.9.0
最終プッシュ
2026-09-30
Checkov部分的

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Only the infrastructure as code checks, for Terraform, CloudFormation, Kubernetes and more.

言語
Python
ライセンス
Apache-2.0
スター
9.1k
最新リリース
3.3.23
最終プッシュ
2026-10-06
Dependency-Check部分的

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Dependency scanning against the NVD, with Maven, Gradle and Ant plugins; no container image scanning.

言語
Java
ライセンス
Apache-2.0
スター
7.7k
最新リリース
v13.0.0
最終プッシュ
2026-10-05
Dependency-Track部分的

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Continuous monitoring of dependencies from SBOMs with policies, without fix pull requests.

言語
Java
ライセンス
Apache-2.0
スター
4.3k
最新リリース
5.1.2
最終プッシュ
2026-10-06
KICS部分的

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Only the infrastructure as code checks, with queries for Terraform, Kubernetes, Docker and more.

ライセンス
Apache-2.0
スター
2.7k
最新リリース
v2.2.0
最終プッシュ
2026-10-06

一対一で比較

Snykについて

提供元
Snyk

Snykの Web サイト ↗