Vigilance vs Anchore
Anchore. Lists what is in a build and flags parts with known bugs. Vigilance finds the update that gained a hidden power, before you install it.
Updated 5 Oct 2026
The Catch Anchore Cannot Make
Anchore lists your parts and flags the ones with known bugs. A brand-new attack has no known bug yet. Vigilance keeps no list. It compares the version you trust with the version you install. It reports any file that can suddenly do more.
A real one: axios, March 2026
axios is one of the most-installed packages on the internet. In release 1.14.1, its package.json gained a hidden install step. That step pulls down a remote-control program. No CVE existed for it, so a list of known bugs had nothing to match. One command sees it:
vigi diff --old ./axios-1.14.0 --new ./axios-1.14.1
HEADS UP. 1 file changed. package.json can now run a hidden helper on install and reach the network.
Run both. Anchore flags the bugs already on record. Vigilance flags the power a file just gained. See them side by side below.
What Anchore Does Well
Anchore makes two open-source tools that many teams use. Syft builds a software bill of materials (SBOM) from an image or a folder. Grype scans container images, directories and SBOMs for known bugs. Grype covers OS packages and language packages for Ruby, Java, JavaScript, Python, .NET, Go, PHP and Rust. It ranks results with EPSS, KEV and a risk score, and it supports OpenVEX. Grype uses the Apache-2.0 licence and Anchore sponsors it. Source: the Grype page.
Anchore Enterprise adds the parts a company needs around those tools. It stores SBOMs in one place, enforces policy and reports on compliance. Anchore lists policy packs for NIST, FedRAMP and DISA standards. It also lists automated SBOM and vulnerability workflows for DORA, CRA and NIS2. A team that must show an auditor an SBOM for every release gets real help here.
Anchore also lists secret and malware identification among its scan types. Source: the Anchore site.
The open-source tools are easy to start with. You install one binary, point it at an image and read a table of results. This low entry cost is a real reason so many teams begin with Grype before they look at anything else.
Where It Falls Short
An SBOM lists the parts in a build. It does not list what each file can do. Two SBOMs from two releases show a changed version number. They do not show that one file gained the power to reach the network.
A scan for known bugs finds a match only after someone reports the bug. A brand-new attack has no report on its first day. The Anchore pages Vigilance read do not say how its malware identification finds new malware that nobody has described yet.
Enterprise pricing is not public. This is normal for the category, but it means you must ask for a quote before you can compare cost.
Anchore tools work best when you feed them the right target. Syft and Grype read an image, a directory or an SBOM that you give them. They do not watch for the moment a new version replaces an old one. You must wire that step into your own pipeline.
Feature Comparison
Anchore lists parts and known bugs, and Vigilance compares what files can do. The table shows how they differ.
| Question | Anchore | Vigilance |
|---|---|---|
| Runs on your own machine | Yes | Yes |
| Builds an SBOM for a release | Yes, with Syft | No |
| Finds known bugs in your dependencies | Yes | No |
| Matches against known malware | Listed as a scan type | No. It keeps no list. |
| Spots a file that can do more than the version before | Not its focus | Yes |
| Looks inside container images | Yes | Yes |
| Reports on compliance for NIST, FedRAMP or CRA | Yes, in Enterprise | No |
| Works with no internet | With a downloaded database | Pro |
When Anchore Is the Better Fit
Choose Anchore if you must produce SBOMs. Syft is free and well known, and Enterprise gives you a place to keep them.
Choose Anchore if your auditor or customer asks for a vulnerability report against a standard such as NIST or FedRAMP. Vigilance does not produce that report.
Choose Anchore if you ship container images and want known-bug scans in every build. Grype is a good free start. Vigilance is not a CVE scanner.
An SBOM Lists Parts, and Vigilance Compares Files
Think of an SBOM as an inventory. It says which packages and versions are in the build. That helps when a new bug is announced, because you can search the inventory for the affected version.
Vigilance answers a question the inventory cannot. A package keeps its name and moves from version 1.14.0 to 1.14.1. Which files changed, and can any of them now do something new? The first run of Vigilance records every file and what it can do. The next run compares. The result is the file that gained a capability, or nothing on a normal day.
How to Use Anchore and Vigilance in One Pipeline
Keep your Syft and Grype steps as they are. Syft writes the SBOM for the build and Grype scans it for known bugs. These steps give you the inventory and the bug report that auditors ask for.
Add a Vigilance step that compares the new build with the last build you trusted. Point it at the folder, the image or the package. The first run records every file and what it can do. Each later run compares against that record.
Read the two outputs for two different questions. Grype answers which known bugs apply to the parts you ship. Vigilance answers whether any file now does something the earlier build did not. A clean Grype report with a Vigilance line on one file is a real case. It means the parts have no report, and one file changed in a way you must read.
Vigilance reads inside deb, rpm, npm, pip, container, MSI and ISO files. It runs on Mac, Linux, Windows and the BSDs. Pro needs no network, so it also fits a build host that cannot reach the internet.
What to Ask Before You Choose
Ask who needs the SBOM. If an auditor or a customer needs one, build it with Syft and keep it. If nobody asks, an SBOM alone adds little to your daily work.
Ask whether you need a policy gate on known bugs. Grype can fail a build on severity. Enterprise adds policy packs and reporting for standards such as NIST and FedRAMP.
Ask what you do when a package keeps its name and changes its behaviour. A bug list has no entry for it. Decide who checks the files of that update, and with which tool.
Ask whether you need the tools to run with no network. Grype works from a downloaded database. Vigilance Pro has no network code in the binary.
Pricing
Syft and Grype are free and open source. Anchore Enterprise has no public price. The pricing page offers a Request Pricing button for the cloud image on AWS and for the container image on Kubernetes. It names commercial tiers Core, Enhanced, Pro and Advanced, and separate government tiers Basic, Premium and Ultimate. It lists no dollar amounts. Source: Anchore pricing.
Vigilance has a Free plan at $0 with the full scanner for up to 50 machines. Free needs a network and sends a signed report of hashes and capabilities only. A name, an email or a file is sent only if you opt in, and each one needs its own yes. Pro works with no network at all. It is flat for the whole company, starts at $999 CAD a month, and the price steps with company size, not with the machine count.
Which One Do You Need?
Anchore lists parts and their known bugs. Vigilance shows the file that gained a capability. They cover different risks, and a team with a compliance duty often needs both.
Read how the two sit among other options in software supply chain security tools, or see real attacks that Vigilance replays.
Known Risk versus New Risk
A bug or a bad package someone already reported, with a name and a number. Most tools work here.
A file that gained a capability it never had, that no report covers yet. Vigilance works here.
Common Questions
Is Vigilance an Anchore alternative?
Yes, for one job. Vigilance shows the file that gained a new capability, on your own machine. It does not make SBOMs or scan for known bugs, so it does not replace Syft or Grype.
What does Vigilance do that Anchore does not?
Vigilance compares the version you trust with the new one and reports the file that can now do more. It reads inside packages, installers and containers.
What does Anchore do that Vigilance does not?
Anchore builds SBOMs, scans for known bugs and, in Enterprise, enforces policy and reports on compliance. Vigilance does none of these.
Are Syft and Grype free?
Yes. Syft and Grype are open-source tools from Anchore. Grype uses the Apache-2.0 licence. Anchore Enterprise is sold by quote.
Does Vigilance need the internet or a cloud account?
The Free plan runs online. Pro runs fully offline, with no cloud account.
Try It on Your Own Software.
Show it the version you run today and the one you are about to install.
Talk to Us
A question, a pilot, or a bigger fleet? Send a note. It reaches a person.