Try our new research platform with insights from 80,000+ expert users

CoreOS Clair vs Trivy comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Container Security
3rd
Average Rating
8.6
Reviews Sentiment
7.8
Number of Reviews
104
Ranking in other categories
Vulnerability Management (6th), Cloud and Data Center Security (5th), Cloud Workload Protection Platforms (CWPP) (4th), Cloud Security Posture Management (CSPM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (3rd)
CoreOS Clair
Ranking in Container Security
26th
Average Rating
8.6
Reviews Sentiment
7.6
Number of Reviews
2
Ranking in other categories
No ranking in other categories
Trivy
Ranking in Container Security
25th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
5
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Andrew W - PeerSpot reviewer
Tells us about vulnerabilities as well as their impact and helps to focus on real issues
Looking at all the different pieces, it has got everything we need. Some of the pieces we do not even use. For example, we do not have Kubernetes Security. We are not running any K8 clusters, so it is good for us. Overall, we find the solution to be fantastic. There can be additional education components. This may not be truly fair to them because of what the product is going for, but it would be great to see additional education for compliance. It is not a criticism of the tool per se, but anything to help non-development resources understand some of the complexities of the cloud is always appreciated. Any additional educational resources are always helpful for security teams, especially those without a development background.
Felipe Giffu - PeerSpot reviewer
An operational system, similar to Linux where you can run your applications inside containers
With CoreOS, you can run your applications inside containers. For example, if you have an application that needs to run on Linux, you can create and install a container. However, it's important to note that you don't install CoreOS inside a container; CoreOS is the host operating system that manages containers. When you mentioned using Nacula as part of your CI/CD pipeline, it means your application is deployed and managed automatically through the CI/CD process. Containers are used to deploy your application within this pipeline, but CoreOS does not run inside these containers. Instead, CoreOS is the base operating system that supports and manages these containers.
Faizan Anwar - PeerSpot reviewer
Open source solution simplifies vulnerability scanning and suggests automation improvements
In our CI/CD pipelines, Trivy lacks built-in functionality for report analysis. It would be beneficial to have an automated report mechanism for outputs in formats like Excel or CSV. Additionally, recommendations based on scanning reports, especially as the world is moving towards AI, would be helpful. Including YAML configuration scanning, in addition to Terraform, would enhance its utility.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is fairly simple. Anybody can use it."
"The UI is responsive and user-friendly."
"SentinelOne's behaviour analytics are valuable because they detect anomalies and malicious behaviour that signature-based solutions might miss."
"SentinelOne Singularity Cloud Security has improved our security posture."
"There's real-time threat detection. It can show threats and find issues based on their severity and helps us with real-time monitoring."
"We're monitoring several cloud accounts with Singularity. It is convenient to identify issues or security failures in any account. It's nice to have all the details we need to solve these issues."
"Singularity Cloud Security's most valuable features are its ease of scalability and comprehensive security measures."
"Cloud Native Security helps us discover vulnerabilities in a cloud environment like open ports that allow people to attack our environment. If someone unintentionally opens a port, we are exposed. Cloud Native Security alerts us so we can remediate the problem. We can also automate it so that Cloud Native Security will fix it."
"CoreOS Clair's best feature is detection accuracy."
"With CoreOS, you can run your applications inside containers. For example, if you have an application that needs to run on Linux, you can create and install a container. However, it's important to note that you don't install CoreOS inside a container; CoreOS is the host operating system that manages containers."
"I definitely recommend Trivy."
"It's customizable, allowing me to add any rules and format HTML templates as I wish."
"The most valuable feature of Trivy is its easy integration with the CI/CD pipeline."
"I can see vulnerabilities in the images of any applications deployed in the Kubernetes environment or as container applications."
"Trivy's open source nature and wide functionality are incredibly valuable."
"One of the great features of Trivy is that it helps me scan items such as AWS credentials and GCP service accounts."
"The most valuable feature of Trivy is its easy integration with the CI/CD pipeline."
"I rate Trivy a nine out of ten."
 

Cons

"SentinelOne currently lacks a break glass account feature, which is critical for implementing Single Sign-On."
"While SentinelOne offers robust security features, its higher cost may present a challenge for budget-conscious organizations."
"Sometimes the Storyline ID is a bit wacky."
"Currently, we would have to export our vulnerability report to an .xlsx file, and review it in an Excel spreadsheet, and then we sort of compile a list from there. It would be cool if there was a way to actually toggle multiple applications for review and then see those file paths on multiple users rather than only one user at a time or only one application at a time."
"The areas with room for improvement include the cost, which is higher compared to other security platforms. The dashboard can also be laggy."
"The documentation that I use for the initial setup can be more detailed or written in a more user-friendly language to avoid troubles."
"Singularity Cloud Security currently lacks a break-glass account function, which is a critical component for implementing Single Sign-On as it allows for regaining access in emergencies."
"Scanning capabilities should be added for the dark web."
"An area for improvement is that CoreOS Clair doesn't provide information about the location of vulnerabilities it detects."
"It can be improved in its support response. They usually take up to seven days to resolve the issue."
"Trivy can improve by providing an output in PDF format."
"In our CI/CD pipelines, Trivy lacks built-in functionality for report analysis."
"The reporting could be a little better."
"Currently, the container image scanning is static. A dynamic scanning capability during runtime would be a significant advantage."
"In our CI/CD pipelines, Trivy lacks built-in functionality for report analysis."
"A dynamic scanning capability during runtime would be a significant advantage."
"Trivy can improve by providing an output in PDF format. Additionally, it takes longer to scan container images built with many layers."
"The reporting could be a little better. When integrating Trivy with CI, the interpretation of the reports could be improved."
 

Pricing and Cost Advice

"Singularity Cloud Security by SentinelOne is cost-efficient."
"We have an enterprise license. It is affordable. I'm not sure, but I think we pay 150,000 rupees per month."
"The licensing is easy to understand and implement, with some flexibility to accommodate dynamic environments."
"I would rate the cost a seven out of ten with ten being the most costly."
"Pricing is based on modules, which was ideal for us."
"I understand that SentinelOne is a market leader, but the bill we received was astronomical."
"It was reasonable pricing for me."
"As a partner, we receive a discount on the licenses."
"CoreOS Clair is open-source and free of charge."
Information not available
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
831,997 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
15%
Manufacturing Company
9%
Government
5%
Financial Services Firm
25%
Computer Software Company
11%
Manufacturing Company
11%
Real Estate/Law Firm
6%
Computer Software Company
17%
Financial Services Firm
15%
Manufacturing Company
12%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
SentinelOne is relatively cheap. If ten is the most expensive, I would rate it a seven.
What needs improvement with PingSafe?
The areas with room for improvement include the cost, which is higher compared to other security platforms. The dashb...
What is your experience regarding pricing and costs for CoreOS Clair?
If you work with CoreOS or OpenShift, you don't need to pay for CoreOS separately. When you pay for OpenShift, you ge...
What needs improvement with CoreOS Clair?
It can be improved in its support response. They usually take up to seven days to resolve the issue.
What is your primary use case for CoreOS Clair?
We use the tool to manage and secure the event file system. CoreOS Clair is an operational system that is very simila...
What needs improvement with Trivy?
The reporting could be a little better. When integrating Trivy with CI, the interpretation of the reports could be im...
What is your primary use case for Trivy?
We are using Trivy for status analysis tests of our code bases, primarily for security and malware testing.
What advice do you have for others considering Trivy?
I would recommend starting to use Trivy and explore the documentation, as it is quite comprehensive. Understanding th...
 

Also Known As

PingSafe
No data available
No data available
 

Overview

 

Sample Customers

Information Not Available
eBay, Veritas, Verizon, SalesForce
Information Not Available
Find out what your peers are saying about CoreOS Clair vs. Trivy and other solutions. Updated: January 2025.
831,997 professionals have used our research since 2012.