Trivy Docker image scanning

Pinning Docker images to a real tag is only step one. Step two is knowing what CVEs sit inside that image before it hits your host. A scanner reads the image layers, lists every OS package and language dependency, and checks each against the CVE feeds. The seven picks below cover local CLI tools, CI runners, and hosted platforms across free and paid tiers.

What to look for in an image scanner

Weigh these before picking one:

Quick comparison

App Best for Runtime Free SBOM Fix guidance
Trivy Default open source scanner Any (CLI, CI) Yes Yes Yes
Grype Anchore-backed CVE scans Any (CLI, CI) Yes Yes Yes
Docker Scout Native Docker Desktop Docker Desktop Free (personal) Yes Yes
Snyk Container Paid CI-first workflow Any Free tier Yes Yes
Clair Registry-side scanning Server Yes Partial Yes
Anchore Engine Policy-driven enterprise Server Yes Yes Yes
Syft SBOM-only companion tool Any (CLI, CI) Yes Yes No

1. Trivy, best default open source pick

Trivy by Aqua Security scans container images, filesystems, git repos, and Kubernetes clusters for CVEs, misconfigurations, and exposed secrets. It reads OS packages and language dependencies out of the box, produces SBOMs, and runs as a CLI, a GitHub Action, or a Kubernetes operator.

The reason to pick it is coverage. Trivy catches things dedicated OS scanners miss (npm/pip CVEs) and things dedicated language scanners miss (base-image OS CVEs) in one pass.

Where it falls short: Enterprise features (policy, dashboards, RBAC) live in Aqua’s paid product. The free CLI does not do fleet-wide reporting.

Pricing: Free and open source (Apache 2.0). Paid Aqua Platform for enterprise.

Platforms: Windows, macOS, Linux (CLI); CI runners; Kubernetes.

Download: trivy.dev · GitHub

Bottom line: The default first install for image scanning.

2. Grype, best Anchore-family option

Grype is the CVE scanner from the Anchore family. It reads SBOMs produced by Syft (its sibling tool) and matches them against public CVE feeds. The reason to use Grype specifically is if you already produce SBOMs with Syft, or if you want cleaner separation between “generate an inventory” and “check the inventory for CVEs”.

Some teams pair Syft + Grype for the SBOM/CVE split; others use Trivy for both in one call.

Where it falls short: Coverage overlaps heavily with Trivy. Picking Grype over Trivy is a matter of preference more than capability.

Pricing: Free and open source (Apache 2.0). Paid Anchore Enterprise for policy and reports.

Platforms: Windows, macOS, Linux (CLI); CI runners.

Download: github.com/anchore/grype

Bottom line: Pick this if you already use Syft or Anchore. Otherwise Trivy.

3. Docker Scout, best native Docker Desktop option

Docker Scout ships inside Docker Desktop and integrates with Docker Hub. Push an image to Docker Hub, and Scout scans it automatically. In Docker Desktop, run docker scout cves <image> to scan locally.

The reason to pick it is that if you already run Docker Desktop, Scout is one command away with no additional install. It also shows a base-image recommendation to reduce the vulnerable surface.

Where it falls short: Free tier covers three repos on Docker Hub. Full org-wide scanning is a paid Docker Business subscription.

Pricing: Free personal tier. Docker Business subscription for team features.

Platforms: Docker Desktop (Windows, macOS, Linux) and Docker Hub.

Download: docs.docker.com/scout

Bottom line: The easiest starting point on Docker Desktop.

4. Snyk Container, best paid CI-first workflow

Snyk Container integrates with GitHub, GitLab, and Bitbucket to scan images referenced in your Dockerfiles and Kubernetes manifests. It opens PRs to bump base images and language packages, and it tracks CVE remediation over time in a dashboard.

The reason to pay is the remediation workflow: Snyk does not just report CVEs, it produces the actual PR that fixes them.

Where it falls short: Free tier is generous for personal use; larger teams need paid seats. Some prefer to keep security tooling open source.

Pricing: Free tier (limited scans). Paid Team and Business plans.

Platforms: Web, CLI, CI/CD integrations.

Download: snyk.io

Bottom line: The pick when you want automated remediation PRs and can budget for it.

5. Clair, best registry-side scanner

Clair by CoreOS/Quay is a server that scans images as they are pushed to a container registry. It stores results and exposes them via an API. Harbor and Quay both integrate Clair natively.

The reason to pick it is if you self-host a registry (Harbor, Quay) and want scans to happen at push time, not at every CI run.

Where it falls short: Server component to run and maintain. Not a CLI you invoke from a laptop.

Pricing: Free and open source (Apache 2.0).

Platforms: Server (Linux, container).

Download: github.com/quay/clair

Bottom line: The pick when you self-host a registry and want centralized scanning.

6. Anchore Engine, best policy-driven enterprise

Anchore Engine (and its successor Anchore Enterprise) scans images, evaluates them against policy rules (no root user, no CVE above High, all packages under two years old), and produces a pass/fail verdict. It plugs into CI as a gate.

The reason to pick it over Trivy or Grype is the policy layer. If compliance needs a signed policy pass, Anchore is built for that flow.

Where it falls short: Enterprise-shaped setup. Overkill for a homelab.

Pricing: Free open source engine. Paid Anchore Enterprise for policy, RBAC, and reporting.

Platforms: Server (Linux, container). CI integrations.

Download: anchore.com · GitHub

Bottom line: The pick when compliance requires policy evaluation, not just a CVE list.

7. Syft, best SBOM-only companion

Syft produces SBOMs (SPDX or CycloneDX) from a container image or filesystem. It is not a CVE scanner. Pair it with Grype for CVE checks, or hand the SBOM to a downstream compliance tool.

The reason to pick Syft alone is if your job is to produce SBOMs for compliance (SLSA, executive order 14028) and CVE analysis happens elsewhere.

Where it falls short: Does not check CVEs on its own. Needs Grype or another tool.

Pricing: Free and open source (Apache 2.0).

Platforms: Windows, macOS, Linux (CLI); CI runners.

Download: github.com/anchore/syft

Bottom line: The pick when SBOM is the deliverable, not the CVE list.

How to pick

FAQ

Which scanner has the best CVE coverage?
Trivy and Grype are effectively tied in 2026 because both consume the same upstream feeds (NVD, GitHub Advisory, Alpine SecDB). Coverage of niche ecosystems (Erlang, R) varies more between them.

Should I scan images in CI or at runtime?
Both. CI-time catches known vulnerabilities before merge. Runtime catches newly disclosed CVEs against images already deployed. Trivy runs in both modes.

How do I fail a CI build on a Critical CVE?
Every scanner in this list supports a severity threshold. Trivy: trivy image --severity CRITICAL --exit-code 1 my-image:1.2.3. Similar flags exist for Grype, Scout, and Snyk.

Is Docker Scout better than Trivy?
Scout’s advantage is the base-image recommendation and the Docker Hub integration. Trivy’s advantage is that it runs anywhere and covers more scan targets. Most teams use both.

Do scanners protect against a supply-chain attack in dependencies?
Partially. They catch known CVEs. They cannot detect a malicious package with no disclosed CVE. Pair with npm/pip signature verification, provenance attestations (SLSA), and Sigstore signing for defense in depth.