Skip to main content

Container image scan

There are alot of container scanning tools, trivy, clair, grype, docker-scan and all?

but whivh one should you use, well if you host your container images on aws ecr, you will know aws ecr has an in repository scanning, both basic and advanced, the advanced scanning scans both os and app.

but the advanced scanning isnt free, its paid, i also read that aws ecr uses clair within their advanced scanning tool.

so i tested trivy, grype and aws ecr in repo advanced scan and here is the results.

AWS ECR Advanced scan​

AWS ECR Advanced scan

Grype Scan​

Grype Scan

Trivy Scan​

Trivy OS Scan Trivy App Scan

What the comparison showed​

From the three scanners tested against the same image, Grype reported more findings than Trivy for this particular image. AWS ECR Advanced Scan also surfaced issues, including application-layer findings.

That does not mean Grype is universally better. Scanners differ in:

  • Vulnerability databases and update cadence
  • OS vs application coverage
  • False positive rates and severity scoring
  • CI integration and output formats

When to choose which​

ScenarioSensible starting point
Images hosted in AWS ECRAWS ECR Basic/Advanced scanning for native integration
Need fast, easy CI integrationTrivy or Grype via their GitHub Actions
Want the broadest detection on a single imageRun both Grype and Trivy and compare, then triage differences
Enterprise policy and reportingUse a scanner that exports SARIF or supports policy enforcement

Completion criterion​

After reading this, you should be able to:

  1. Explain why no single scanner catches everything.
  2. Pick Trivy, Grype, or AWS ECR scanning based on where your images live and your CI setup.
  3. Run at least one container scan before an image reaches production.

Comments