Container image scan
There are alot of container scanning tools, trivy, clair, grype, docker-scan and all?
but whivh one should you use, well if you host your container images on aws ecr, you will know aws ecr has an in repository scanning, both basic and advanced, the advanced scanning scans both os and app.
but the advanced scanning isnt free, its paid, i also read that aws ecr uses clair within their advanced scanning tool.
so i tested trivy, grype and aws ecr in repo advanced scan and here is the results.
AWS ECR Advanced scanβ

Grype Scanβ

Trivy Scanβ


What the comparison showedβ
From the three scanners tested against the same image, Grype reported more findings than Trivy for this particular image. AWS ECR Advanced Scan also surfaced issues, including application-layer findings.
That does not mean Grype is universally better. Scanners differ in:
- Vulnerability databases and update cadence
- OS vs application coverage
- False positive rates and severity scoring
- CI integration and output formats
When to choose whichβ
| Scenario | Sensible starting point |
|---|---|
| Images hosted in AWS ECR | AWS ECR Basic/Advanced scanning for native integration |
| Need fast, easy CI integration | Trivy or Grype via their GitHub Actions |
| Want the broadest detection on a single image | Run both Grype and Trivy and compare, then triage differences |
| Enterprise policy and reporting | Use a scanner that exports SARIF or supports policy enforcement |
Completion criterionβ
After reading this, you should be able to:
- Explain why no single scanner catches everything.
- Pick Trivy, Grype, or AWS ECR scanning based on where your images live and your CI setup.
- Run at least one container scan before an image reaches production.