# Grype: how AI models rank it, September 2026

IT AI Recommendation Index, September 2026 Edition. Named in 19 judge labels across 2 categories by 10 of 12 models. Page: https://it-ai-index.com/vendors/grype/

## Standing by category

| Category | Share | Rank | Negative rate | Labels |
|---|---|---|---|---|
| Software composition analysis | 0% | 15 | 7% | 14 |
| Container and Kubernetes security | 0% | 23 | 20% | 5 |

## What the models said for it

- "utilize their modern stateless CLI tools, Syft (for SBOM generation) and Grype (for vulnerability scanning)" (Gemini 3.5 Flash, Container security)
- "Low FPs (6/41), SBOM-native | Slower (2min+), pair needed | Already using Anchore ecosystem" (Grok 4.1 Fast, SCA)
- "Container-focused teams | Lower false positives, purely focused on vuln matching" (DeepSeek V4 Flash, SCA)
- "Combine Grype + Syft if you: Want the most accurate vulnerability detection" (Kimi K2, SCA)

## And against it

- "Build-time scanners like Trivy, Grype, and Clair can find CVEs and misconfigurations, but they do not detect runtime threats." (Perplexity Sonar, Container security)
- "Less broad (focuses on containers/images, pair with Syft for SBOM/SCA)" (Grok 4.1 Fast, SCA)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
