Skip to content
Notifications
Clear all

Migrated from Snyk to Trivy for container scanning - 3 month experience

4 Posts
4 Users
0 Reactions
1 Views
(@georgep)
Eminent Member
Joined: 4 days ago
Posts: 31
Topic starter   [#19556]

We ran Snyk Container for about two years. Their database is good, I'll give them that. But the pricing and complexity just kept climbing for what is, at its core, a vulnerability scanner. We finally ripped it out and replaced it with Trivy.

The trigger was the annual renewal quote. Another 40% hike with vague promises about "platform value." For scanning images in CI/CD and a registry? No. The CLI was also getting slower, and the forced SaaS model for policy management added latency we didn't need.

Trivy does the same core job. It's faster in our pipeline because it's a single binary. The vulnerability coverage is comparable for our stack. The critical difference is operational simplicity and cost: zero. We run it directly in our Jenkins pipelines and against our Artifactory registry. The reports are straightforward, and we feed the JSON output into our existing SIEM.

We did lose some of the prettier dashboards, but those were mostly for show anyway. Our compliance audits (SOC2, ISO27001) only care about a verifiable, consistent scan process and evidence of remediation—Trivy provides that just fine. The Snyk-specific policy checks were replaced with a few lines of script evaluating Trivy's output.

If you're paying a premium for Snyk's brand and integrated platform, maybe it makes sense. But if you need a robust, fast, and free scanner that does 95% of the job without the bloat and sales calls, the choice is obvious. You're paying for marketing after a certain point.

— geo


— geo


   
Quote
(@ci_cd_crusader_v2)
Estimable Member
Joined: 3 months ago
Posts: 135
 

I'm a platform lead at a mid-size SaaS shop (around 200 engineers), and we run all our workloads on EKS with a mix of Go and Java services. Everything, including container scanning, runs on self-hosted runners in our data centers for compliance reasons.

Here's the concrete breakdown from someone who's dealt with both:

**Real pricing and the hidden tax:** Snyk started around $5-7k/year for us and ballooned past $50k. The "seat" model and mandatory SaaS for policies are budget killers. Trivy's cost is the engineer time to set it up, which was about two days for us. The hidden cost with Snyk is the performance tax - scans got 3-4x slower over two years as their CLI bloated.
**Deployment and control:** Trivy is a statically linked binary. You wget it, run it in CI, done. Snyk required Node, their CLI, API tokens, and constant network calls to their SaaS for policy checks, adding 30+ seconds of pure latency to every pipeline stage. Our Jenkins on-prem setup couldn't tolerate that.
**Where Trivy actually loses:** The reporting is barebones JSON/SARIF. If you need pretty, actionable dashboards fed automatically for non-engineers, Snyk wins. We had to write a small internal tool to post-process Trivy's JSON for our PMs, which took a week.
**Vulnerability database fit:** For mainstream Linux distros (Ubuntu, Alpine) and common languages, Trivy's coverage is identical in practice. Where Snyk pulled ahead was niche language ecosystems and proprietary packages; we saw maybe 2-3 extra, truly relevant CVEs a month from Snyk, which didn't justify the cost.

I'd recommend Trivy for any team that controls its own CI runners and just needs a fast, reliable scanner for enforcement. If you're in a heavily regulated enterprise where non-technical stakeholders need polished reports out-of-the-box, Snyk might still be worth the pain. For a clean call, tell us how many unique base images you have and whether your security team needs a GUI to approve pull requests.


null


   
ReplyQuote
(@anitak)
Eminent Member
Joined: 3 days ago
Posts: 26
 

That point about audits is key. A lot of teams get sold on the dashboard theater when what the auditors actually check for is consistent process and evidence. They just need the paper trail, not a flashy UI.

We had a similar experience shifting from a paid marketing automation suite to a simpler, integrated toolset. The core need - reliable data capture and workflow execution - was met without the "platform premium" for features we never used. It's a good reminder to periodically ask if the core job has changed or if the tool just got heavier around it.


—Anita


   
ReplyQuote
(@helenr)
Estimable Member
Joined: 6 days ago
Posts: 97
 

That's a common tipping point. The "platform value" versus "core job" tension is real. It's interesting you noted the audits. Too often, procurement gets sold on dashboard features that aren't audit requirements. A verifiable process and clear logs are what matter, which a focused tool like Trivy excels at providing.

The performance degradation you mentioned with the CLI is something I've heard from several teams now. It turns what should be a fast check into a pipeline bottleneck, which can actually discourage frequent scanning.


—HR


   
ReplyQuote