Pinning Docker images to a real tag is only step one. Step two is knowing what CVEs sit inside that image before it hits your host. A scanner reads the image layers, lists every OS package and language dependency, and checks each against the CVE feeds. The seven picks below cover local CLI tools, CI runners, and hosted platforms across free and paid tiers.
What to look for in an image scanner
Weigh these before picking one:
- Coverage. OS-package CVEs (RPM, DEB, APK, Alpine) plus language-package CVEs (npm, pip, gem, cargo, Go modules). Not every tool catches both.
- Fix guidance. A raw CVE list is noise. Good tools show the specific package version to upgrade to.
- SBOM output. SPDX or CycloneDX software-bill-of-materials output is now a compliance requirement in some sectors.
- CI integration. Fail the build on a Critical CVE, or open a PR to bump the package.
- Runtime scan. Some tools also watch running containers for behavior anomalies. Enterprise-only in most cases.
Quick comparison
| App | Best for | Runtime | Free | SBOM | Fix guidance |
|---|---|---|---|---|---|
| Trivy | Default open source scanner | Any (CLI, CI) | Yes | Yes | Yes |
| Grype | Anchore-backed CVE scans | Any (CLI, CI) | Yes | Yes | Yes |
| Docker Scout | Native Docker Desktop | Docker Desktop | Free (personal) | Yes | Yes |
| Snyk Container | Paid CI-first workflow | Any | Free tier | Yes | Yes |
| Clair | Registry-side scanning | Server | Yes | Partial | Yes |
| Anchore Engine | Policy-driven enterprise | Server | Yes | Yes | Yes |
| Syft | SBOM-only companion tool | Any (CLI, CI) | Yes | Yes | No |
1. Trivy, best default open source pick
Trivy by Aqua Security scans container images, filesystems, git repos, and Kubernetes clusters for CVEs, misconfigurations, and exposed secrets. It reads OS packages and language dependencies out of the box, produces SBOMs, and runs as a CLI, a GitHub Action, or a Kubernetes operator.
The reason to pick it is coverage. Trivy catches things dedicated OS scanners miss (npm/pip CVEs) and things dedicated language scanners miss (base-image OS CVEs) in one pass.
Where it falls short: Enterprise features (policy, dashboards, RBAC) live in Aqua’s paid product. The free CLI does not do fleet-wide reporting.
Pricing: Free and open source (Apache 2.0). Paid Aqua Platform for enterprise.
Platforms: Windows, macOS, Linux (CLI); CI runners; Kubernetes.
Bottom line: The default first install for image scanning.
2. Grype, best Anchore-family option
Grype is the CVE scanner from the Anchore family. It reads SBOMs produced by Syft (its sibling tool) and matches them against public CVE feeds. The reason to use Grype specifically is if you already produce SBOMs with Syft, or if you want cleaner separation between “generate an inventory” and “check the inventory for CVEs”.
Some teams pair Syft + Grype for the SBOM/CVE split; others use Trivy for both in one call.
Where it falls short: Coverage overlaps heavily with Trivy. Picking Grype over Trivy is a matter of preference more than capability.
Pricing: Free and open source (Apache 2.0). Paid Anchore Enterprise for policy and reports.
Platforms: Windows, macOS, Linux (CLI); CI runners.
Download: github.com/anchore/grype
Bottom line: Pick this if you already use Syft or Anchore. Otherwise Trivy.
3. Docker Scout, best native Docker Desktop option
Docker Scout ships inside Docker Desktop and integrates with Docker Hub. Push an image to Docker Hub, and Scout scans it automatically. In Docker Desktop, run docker scout cves <image> to scan locally.
The reason to pick it is that if you already run Docker Desktop, Scout is one command away with no additional install. It also shows a base-image recommendation to reduce the vulnerable surface.
Where it falls short: Free tier covers three repos on Docker Hub. Full org-wide scanning is a paid Docker Business subscription.
Pricing: Free personal tier. Docker Business subscription for team features.
Platforms: Docker Desktop (Windows, macOS, Linux) and Docker Hub.
Download: docs.docker.com/scout
Bottom line: The easiest starting point on Docker Desktop.
4. Snyk Container, best paid CI-first workflow
Snyk Container integrates with GitHub, GitLab, and Bitbucket to scan images referenced in your Dockerfiles and Kubernetes manifests. It opens PRs to bump base images and language packages, and it tracks CVE remediation over time in a dashboard.
The reason to pay is the remediation workflow: Snyk does not just report CVEs, it produces the actual PR that fixes them.
Where it falls short: Free tier is generous for personal use; larger teams need paid seats. Some prefer to keep security tooling open source.
Pricing: Free tier (limited scans). Paid Team and Business plans.
Platforms: Web, CLI, CI/CD integrations.
Download: snyk.io
Bottom line: The pick when you want automated remediation PRs and can budget for it.
5. Clair, best registry-side scanner
Clair by CoreOS/Quay is a server that scans images as they are pushed to a container registry. It stores results and exposes them via an API. Harbor and Quay both integrate Clair natively.
The reason to pick it is if you self-host a registry (Harbor, Quay) and want scans to happen at push time, not at every CI run.
Where it falls short: Server component to run and maintain. Not a CLI you invoke from a laptop.
Pricing: Free and open source (Apache 2.0).
Platforms: Server (Linux, container).
Download: github.com/quay/clair
Bottom line: The pick when you self-host a registry and want centralized scanning.
6. Anchore Engine, best policy-driven enterprise
Anchore Engine (and its successor Anchore Enterprise) scans images, evaluates them against policy rules (no root user, no CVE above High, all packages under two years old), and produces a pass/fail verdict. It plugs into CI as a gate.
The reason to pick it over Trivy or Grype is the policy layer. If compliance needs a signed policy pass, Anchore is built for that flow.
Where it falls short: Enterprise-shaped setup. Overkill for a homelab.
Pricing: Free open source engine. Paid Anchore Enterprise for policy, RBAC, and reporting.
Platforms: Server (Linux, container). CI integrations.
Download: anchore.com · GitHub
Bottom line: The pick when compliance requires policy evaluation, not just a CVE list.
7. Syft, best SBOM-only companion
Syft produces SBOMs (SPDX or CycloneDX) from a container image or filesystem. It is not a CVE scanner. Pair it with Grype for CVE checks, or hand the SBOM to a downstream compliance tool.
The reason to pick Syft alone is if your job is to produce SBOMs for compliance (SLSA, executive order 14028) and CVE analysis happens elsewhere.
Where it falls short: Does not check CVEs on its own. Needs Grype or another tool.
Pricing: Free and open source (Apache 2.0).
Platforms: Windows, macOS, Linux (CLI); CI runners.
Download: github.com/anchore/syft
Bottom line: The pick when SBOM is the deliverable, not the CVE list.
How to pick
- Default first install: Trivy.
- Already use Anchore or Syft: Grype.
- Already run Docker Desktop: Docker Scout.
- Want remediation PRs: Snyk Container.
- Self-host Harbor or Quay: Clair.
- Compliance policy gate: Anchore Enterprise.
- SBOM is the deliverable: Syft + Grype.
FAQ
Which scanner has the best CVE coverage?
Trivy and Grype are effectively tied in 2026 because both consume the same upstream feeds (NVD, GitHub Advisory, Alpine SecDB). Coverage of niche ecosystems (Erlang, R) varies more between them.
Should I scan images in CI or at runtime?
Both. CI-time catches known vulnerabilities before merge. Runtime catches newly disclosed CVEs against images already deployed. Trivy runs in both modes.
How do I fail a CI build on a Critical CVE?
Every scanner in this list supports a severity threshold. Trivy: trivy image --severity CRITICAL --exit-code 1 my-image:1.2.3. Similar flags exist for Grype, Scout, and Snyk.
Is Docker Scout better than Trivy?
Scout’s advantage is the base-image recommendation and the Docker Hub integration. Trivy’s advantage is that it runs anywhere and covers more scan targets. Most teams use both.
Do scanners protect against a supply-chain attack in dependencies?
Partially. They catch known CVEs. They cannot detect a malicious package with no disclosed CVE. Pair with npm/pip signature verification, provenance attestations (SLSA), and Sigstore signing for defense in depth.