IT AI Index
Index Vendors › Grype · September 2026 Edition
2 categories · Ranked

Grype

37Judge labels
0First choices
2Negative labels
12 of 12Models named it
2Categories
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
0% in SCA for mid-market buyers
Rank 15 of 49 in the mid-market standingaccepted challenger
0 of 12 models made it the first choice on the direct prompt; 7% of its 14 labels there were negative.
By buyer segmentRead the same way at every buyer size.
In sca · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named Grype for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Software composition analysisDeveloper platform0%15 of 497%14accepted challenger
Container and Kubernetes securityCloud and infrastructure0%23 of 7820%5under 10 labels · led by Aqua Security at 18%

Movement

This is the first edition on this tier, so no move can be computed for Grype yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated Grype across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.500000
GPT-5.4 mini01001
Gemini 3.5 Flash01001
Perplexity Sonar00112
Grok 4.1 Fast01113
Mistral Small01001
DeepSeek V4 Flash02002
Llama 4 Maverick00000
Qwen 3.7 Flash00101
Kimi K203003
GLM 4.7 FlashX02103
MiniMax M2.501102

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct0 labelsNone
Paraphrase19 labelsNone
Comparative3 labelsNone
Budget-constrained8 labelsNone
Scale-constrained0 labelsNone
Negative7 labels1not counted in share
First choiceAlternativeMentionNegative37 labels in all, every segment counted; 0 of the 1 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“utilize their modern stateless CLI tools, Syft (for SBOM generation) and Grype (for vulnerability scanning)” Gemini 3.5 Flash · Container security · negative prompt · alternative
“Low FPs (6/41), SBOM-native | Slower (2min+), pair needed | Already using Anchore ecosystem” Grok 4.1 Fast · SCA · paraphrase prompt · alternative
“Container-focused teams | Lower false positives, purely focused on vuln matching” DeepSeek V4 Flash · SCA · paraphrase prompt · alternative
“Combine Grype + Syft if you: Want the most accurate vulnerability detection” Kimi K2 · SCA · budget prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“Build-time scanners like Trivy, Grype, and Clair can find CVEs and misconfigurations, but they do not detect runtime threats.” Perplexity Sonar · Container security · negative prompt · soft negative
“Less broad (focuses on containers/images, pair with Syft for SBOM/SCA)” Grok 4.1 Fast · SCA · budget prompt · soft negative

Named alongside

The products named in the same answers as Grype, over the 37 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and Grype was named but was not.
ProductSame answerTook the first choice insteadHead to head
Trivy36 of 3718Not in the top three
OWASP Dependency-Check23 of 374Not in the top three
OSV-Scanner18 of 371Not in the top three
Syft14 of 370Not in the top three
Snyk Open Source13 of 375Not in the top three
OWASP Dependency-Track9 of 373Not in the top three
Falco8 of 372Not in the top three
Kubescape5 of 371Not in the top three
Black Duck5 of 370Not in the top three
Prisma Cloud5 of 370Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named Grype. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 31 of the 37 answers that named Grype and are not a share of its labels.

Domains cited

appsecsanta.com26
safeguard.sh23
aikido.dev19
endorlabs.com17
guideflow.com14
cve.optibot.re12
ox.security11
github.com10
expertinsights.com9
snyk.io8

149 of the 149 domain citations in answers naming Grype came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as Grype

What the judge wrote, as written, with how often. The vendor table decides that these count as Grype; a claim can dispute any of them.
Grype (Anchore) 3Grype (+Syft) 1Grype (by Aqua Security) 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Grype's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Grype, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at grype.com is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.