{"slug":"grype","name":"Grype","domain":"github.com","verdict":"As of 2026-07-16, ChatGPT, Claude, Gemini, Grok collectively rank Grype #2 of 5 for open-source container image scanner (one of 4 leaderboards it appears on). Source: https://modelsagree.com/product/grype (modelsagree.com, CC BY 4.0).","best_rank":2,"categories":4,"brief":{"category":"best-open-source-container-image-scanner","title":"Best open-source container image scanner","rank":2,"of":5,"top":"Trivy","day":"2026-07-17","why":[{"t":"SBOM-first workflow","m":["ChatGPT","Claude","Gemini","Grok"],"q":"the cleanest SBOM-first workflow"},{"t":"fast pure vulnerability scanning","m":["ChatGPT","Claude","Gemini","Grok"],"q":"Extremely fast pure vulnerability scanning on images/filesystems/SBOMs"},{"t":"pairs with Syft","m":["ChatGPT","Claude","Gemini","Grok"],"q":"pairs with Syft, the strongest open-source SBOM generator"},{"t":"strong risk prioritization","m":["Grok"],"q":"strong risk prioritization via EPSS/KEV scoring"}],"gap":[{"t":"all-in-one scope","m":["ChatGPT","Claude","Gemini","Grok"],"q":"one binary scans images, filesystems, git repos, IaC, secrets, and generates SBOMs"},{"t":"licenses and image-configuration checks","m":["ChatGPT","Gemini","Grok"],"q":"licenses, and image-configuration checks in one open-source tool"}],"fix":[{"t":"vulnerability scanning only","m":["ChatGPT","Claude","Gemini","Grok"],"q":"Vulnerability scanning only — no IaC, secret, or misconfiguration scanning"},{"t":"running a second tool","m":["ChatGPT","Claude","Gemini","Grok"],"q":"most teams end up running a second tool alongside it"}]},"entries":[{"slug":"best-open-source-container-image-scanner","title":"Best open-source container image scanner","rank":2,"of":5,"score":16,"appearances":4,"modelRanks":{"ChatGPT":2,"Claude":2,"Gemini":2,"Grok":2},"reason":"Near-tie with Trivy for pure vulnerability scanning; excellent package identification with Syft, strong SBOM/VEX support, clear CI policies, and fully local operation.","reasons":[{"model":"ChatGPT","reason":"Near-tie with Trivy for pure vulnerability scanning; excellent package identification with Syft, strong SBOM/VEX support, clear CI policies, and fully local operation."},{"model":"Claude","reason":"Anchore's scanner pairs with Syft, the strongest open-source SBOM generator, giving the cleanest SBOM-first workflow — generate once, rescan the SBOM continuously without re-pulling images; matching accuracy is competitive with or better than Trivy on language packages, and the codebase is focused rather than sprawling. Near-tie with Trivy for pure image scanning; Trivy wins on all-in-one scope."},{"model":"Gemini","reason":"Fast, dedicated vulnerability matcher optimized for SBOM-first workflows with Syft, allowing rapid rescanning of generated SBOMs without pulling original images."},{"model":"Grok","reason":"Extremely fast pure vulnerability scanning on images/filesystems/SBOMs (often 30-40% faster than Trivy for CVE matching); pairs excellently with Syft for modular SBOM workflows; strong risk prioritization via EPSS/KEV scoring; reduced false positives in recent updates; ideal complement or alternative for focused vuln detection."}],"fixes":[{"model":"ChatGPT","fix":"It is narrower than Trivy, so teams need separate tools for secrets and misconfiguration scanning."},{"model":"Claude","fix":"Vulnerability scanning only — no IaC, secret, or misconfiguration scanning, so most teams end up running a second tool alongside it."},{"model":"Gemini","fix":"Strictly focused on vulnerability scanning, requiring external tools for IaC, secrets, and compliance checks."},{"model":"Grok","fix":"Narrower scope (vuln scanning only, no built-in IaC/secrets/IaC); requires pairing for full coverage."}],"updated":"2026-07-16","api":"https://modelsagree.com/api/v1/best/best-open-source-container-image-scanner.json"},{"slug":"best-container-image-vulnerability-scanner","title":"Best container image vulnerability scanner","rank":3,"of":9,"score":9,"appearances":3,"modelRanks":{"Claude":3,"Gemini":4,"Grok":2},"reason":"Fastest and most accurate focused image/filesystem vulnerability scanner with excellent SBOM (Syft) integration, low false positives, and strong Anchore-backed database coverage for pure vuln workflows.","reasons":[{"model":"Grok","reason":"Fastest and most accurate focused image/filesystem vulnerability scanner with excellent SBOM (Syft) integration, low false positives, and strong Anchore-backed database coverage for pure vuln workflows."},{"model":"Claude","reason":"Anchore's OSS scanner with arguably the best match accuracy in open source, pairs cleanly with Syft for SBOM-first workflows, simple CI drop-in, and transparent vulnerability matching logic you can audit"},{"model":"Gemini","reason":"Extremely fast, lightweight, and focused static scanner that integrates seamlessly with Syft for SBOM-first vulnerability detection."}],"fixes":[{"model":"Claude","fix":"Narrower feature surface than Trivy (no IaC/secrets scanning), so teams needing one tool for everything pick the competitor"},{"model":"Gemini","fix":"Expand native capability to scan for misconfigurations and secrets out of the box without requiring external utilities."},{"model":"Grok","fix":"Expand native support for misconfigurations and secrets to match Trivy's breadth without sacrificing its speed edge."}],"updated":"2026-07-10","rank_history":{"days":["2026-06-29","2026-06-30","2026-07-08","2026-07-09","2026-07-10"],"ranks":[4,5,3,4,null]},"api":"https://modelsagree.com/api/v1/best/best-container-image-vulnerability-scanner.json"},{"slug":"best-dependency-scanning-tools-for-open-source-maintainers","title":"Best dependency scanning tools for open-source maintainers","rank":7,"of":7,"score":2,"appearances":1,"modelRanks":{"Grok":4},"reason":"Lightweight, scriptable, high-precision container/dependency vuln scanning (pairs perfectly with Syft SBOMs), fast and accurate in benchmarks, strong OSS maintenance; ideal complement for image-focused OSS projects.","reasons":[{"model":"Grok","reason":"Lightweight, scriptable, high-precision container/dependency vuln scanning (pairs perfectly with Syft SBOMs), fast and accurate in benchmarks, strong OSS maintenance; ideal complement for image-focused OSS projects."}],"fixes":[{"model":"Grok","fix":"Narrower scope (best with SBOM workflow, less all-in-one than Trivy) and ecosystem coverage gaps outside containers (not primary for pure app-level multi-lang scanning)."}],"updated":"2026-07-17","api":"https://modelsagree.com/api/v1/best/best-dependency-scanning-tools-for-open-source-maintainers.json"},{"slug":"best-container-scanner-for-fedramp-compliance","title":"Best container scanner for FedRAMP compliance","rank":8,"of":10,"score":2,"appearances":1,"modelRanks":{"Grok":4},"reason":"Fast, accurate open-source scanner with strong SBOM/vuln detection, EPSS/KEV integration for better prioritization, and seamless tie-in to Anchore Enterprise for FedRAMP scaling; high value for practitioners balancing cost and effectiveness in pipelines.","reasons":[{"model":"Grok","reason":"Fast, accurate open-source scanner with strong SBOM/vuln detection, EPSS/KEV integration for better prioritization, and seamless tie-in to Anchore Enterprise for FedRAMP scaling; high value for practitioners balancing cost and effectiveness in pipelines."}],"fixes":[{"model":"Grok","fix":"Lacks built-in enterprise policy/ConMon reporting (requires additional tooling or Anchore Enterprise for full FedRAMP ConMon)."}],"updated":"2026-07-16","api":"https://modelsagree.com/api/v1/best/best-container-scanner-for-fedramp-compliance.json"}],"page":"https://modelsagree.com/product/grype","check":"https://modelsagree.com/check?q=Grype","updated":"2026-08-10T18:18:45.051Z","attribution":"modelsagree.com, CC BY 4.0"}