# Trivy vs GitHub Advanced Security: which do AI models recommend for SCA, October 2026

IT AI Recommendation Index, October 2026 Edition, Software composition analysis. Zero of fourteen models named Trivy first on the direct prompt; one named GitHub Advanced Security. Page: https://it-ai-index.com/developer/software-composition-analysis/trivy-vs-github-advanced-security/

| | First-choice share | Rank | Negative rate | Labels | Models naming it |
|---|---|---|---|---|---|
| Trivy | 31% | #1 of 17 | 11% | 27 | 13 of 14 |
| GitHub Advanced Security | 2% | #8 of 17 | 6% | 18 | 11 of 14 |

## The direct prompt, model by model

- GLM 4.7 FlashX: github advanced security first (first choices: GitHub Advanced Security, Snyk Open Source) (alternatives: Black Duck, Endor Labs, FOSSA, Mend.io, Sonatype Lifecycle)
- Mistral Small: neither first, one named (first choices: Mend.io) (alternatives: GitHub Advanced Security, Insignary Clarity)
- Qwen 3.7 Flash: neither first, one named (first choices: Mend.io) (alternatives: GitHub Advanced Security, Snyk Open Source)
- Kimi K2: neither first, one named (first choices: Mend.io, Snyk Open Source) (alternatives: GitHub Advanced Security, GitHub Dependabot, Sonatype Lifecycle, Trivy)
- MiniMax M2.5: neither first, one named (first choices: Snyk Open Source, Sonatype Lifecycle) (alternatives: Black Duck, FOSSA, GitHub Advanced Security)
- Claude Haiku 4.5: neither named (first choices: Mend.io) (alternatives: Black Duck, Endor Labs, FOSSA, Snyk Open Source, Sonatype Lifecycle)
- GPT-5.4 mini: neither named (first choices: Snyk Open Source) (alternatives: FOSSA, OWASP Dependency-Check, OWASP Dependency-Track)
- Gemini 3.5 Flash: neither named (first choices: Aikido Security) (alternatives: Endor Labs, Mend.io, Snyk Open Source)
- Perplexity Sonar: neither named (first choices: Mend.io) (alternatives: Black Duck, Snyk Open Source, Sonatype Lifecycle)
- Grok 4.1 Fast: neither named (first choices: Snyk Open Source) (alternatives: Mend.io, Sonatype Lifecycle)
- DeepSeek V4 Flash: neither named (first choices: Snyk Open Source) (alternatives: Mend.io, Sonatype Lifecycle)
- Llama 4 Maverick: neither named (first choices: Mend.io)
- GPT-6 Luna: neither named (first choices: Snyk Open Source) (alternatives: GitHub's built-in supply-chain tools, Mend.io, Sonatype Lifecycle)
- Muse Glimmer 30B: neither named (first choices: Mend.io) (alternatives: Snyk Open Source, Sonatype Lifecycle)

## What the models said about Trivy

- "free options like Trivy being the best zero-budget choice but typically requiring more tuning than commercial offerings" (Muse Glimmer 30B, negative prompt, soft negative)
- "Trivy disclosed a 2026 compromise involving a malicious release and GitHub Action tags, so pin and verify the tooling" (GPT-6 Luna, paraphrase prompt, soft negative)
- "I'd recommend Trivy (from Aqua Security) as the top open-source dependency vulnerability scanner for a mid-sized B2B company." (Grok 4.1 Fast, paraphrase prompt, first choice)

## What the models said about GitHub Advanced Security

- "GHAS is expensive and is sold as a bundled suite. If you only want SCA, paying for the entire suite might not make financial sense." (Gemini 3.5 Flash, direct prompt, soft negative)
- "For GitHub\u2011centric teams: Start with GitHub Advanced Security" (GLM 4.7 FlashX, direct prompt, first choice)
- "Dependabot SCA + secret/code scanning from ~$19/user/mo (free for public repos). Native if your workflow is GitHub-centric." (Grok 4.1 Fast, budget prompt, alternative)

Share is the count of first choices across the direct, paraphrase, budget and scale prompts over all fourteen models, for a mid-market B2B company; rank is within the category. Comparisons are drawn for the top eight products in each category. Published under CC BY 4.0; the output is the models' output, and nothing here is a recommendation by the index.
