7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source Socket alternatives

A curated, ranked list of the 4 best open-source alternatives to Socket.

The best open-source alternative to Socket is Trivy. If that doesn't suit you, other good options are Grype, Dependency-Track and Somo.

Socket alternatives are mainly security tools, but some are also developer tools. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and 4 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Trivy

A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes.

GitHub stars
38k
Last commit
yesterday
Latest release
v0.75.0
Licence
Apache-2.0
trivy.devTrivy homepage screenshot

Trivy is a security scanner from Aquasec, written in Go and released under the Apache-2.0 license. It has scanners that look for different security issues and targets where those issues can be found. The README describes it as comprehensive and versatile, and it covers the major programming languages, operating systems and platforms.

Targets include container images, filesystems, remote Git repositories, virtual machine images and Kubernetes. Scanners look for OS packages and software dependencies in use, which produces an SBOM, known vulnerabilities (CVEs), infrastructure-as-code issues and misconfigurations, sensitive information and secrets, and software licenses. Its topics reference DevSecOps and vulnerability scanning.

Trivy is available through most common channels, including Homebrew, a Docker image and downloadable binaries, and integrates with platforms such as GitHub Actions, a Kubernetes operator and a VS Code plugin. Canary builds are produced with each push to the main branch. It suits developers, platform teams and security engineers who want to scan images and code in CI pipelines.

Key features

  • Scans container images and filesystems
  • Scans Git repositories and Kubernetes
  • Known vulnerability (CVE) detection
  • IaC misconfiguration and secret detection
  • SBOM generation and license scanning
  • GitHub Actions and VS Code integrations

Pricing: Free and open source under the Apache-2.0 license.

Grype

Command-line vulnerability scanner that checks container images, filesystems and SBOMs for known security issues in OS and language packages.

GitHub stars
13k
Last commit
today
Latest release
v0.120.0
Licence
Apache-2.0

Grype is an open-source vulnerability scanner for container images and filesystems. You point it at an image, a directory or a software bill of materials (SBOM), and it reports known vulnerabilities in the packages it finds, so teams can catch risky dependencies before software ships.

It covers major operating system package ecosystems such as Alpine, Debian, Ubuntu, RHEL, Oracle Linux and Amazon Linux, as well as language packages for Ruby, Java, JavaScript, Python, .NET, Go, PHP and Rust. Docker, OCI and Singularity image formats are supported. Results can be prioritized with EPSS, KEV and risk scoring, and OpenVEX documents can filter or augment findings.

Grype is written in Go and released under the Apache-2.0 license. It can be installed through Homebrew, Docker, Chocolatey, MacPorts and other routes, and the documentation includes a getting started guide, CLI reference and configuration reference. Development is sponsored by Anchore, which also handles commercial support requests for Grype and its companion tool Syft.

Key features

  • Scans container images, filesystems and SBOMs
  • OS package support for Alpine, Debian, Ubuntu, RHEL
  • Language package support including Python, Go, Java
  • Docker, OCI and Singularity image formats
  • EPSS, KEV and risk-score prioritization
  • OpenVEX filtering of scan results

Pricing: Free and open source under the Apache-2.0 license; commercial support is available from Anchore.

Read more about GrypeGitHub

Dependency-Track

An OWASP component analysis platform that uses SBOMs to identify and reduce risk in the software supply chain, with vulnerability tracking across projects.

GitHub stars
4.3k
Last commit
yesterday
Latest release
5.1.1
Licence
Apache-2.0
Self-hosted
Yes
dependencytrack.orgDependency-Track homepage screenshot

Dependency-Track is a component analysis platform from the OWASP community that helps organizations identify and reduce risk in their software supply chain. It takes an approach built on the Software Bill of Materials (SBOM), analyzing the components listed for each project.

Repository topics show how it works with CycloneDX SBOMs, Package URLs, the National Vulnerability Database and OSS Index to detect known vulnerabilities in components, supporting software composition analysis, DevSecOps and security automation. A Docker Compose quickstart lets you get a local instance running in a few minutes.

Version 5 is the current line, while version 4 is in maintenance mode on the 4.14.x branch and reaches end-of-life in December 2026, with a migration guide provided. The frontend, documentation and Helm charts live in separate repositories, a monthly community meeting is open to users, and the project is written in Java under the Apache-2.0 license.

Key features

  • SBOM-based component analysis
  • CycloneDX and Package URL support
  • Vulnerability data from NVD and OSS Index
  • Software supply chain risk tracking
  • Docker Compose quickstart
  • Helm charts for deployment

Pricing: Free and open source under the Apache-2.0 licence.

Somo

Human-friendly command-line replacement for netstat that lists sockets and ports in a readable table, with filtering, sorting, and process killing.

GitHub stars
2.6k
Last commit
5 days ago
Latest release
v1.4.0
Licence
MIT
Self-hosted
Yes
crates.ioSomo homepage screenshot

Somo is a Rust command-line tool for monitoring sockets and ports on Linux and macOS, designed as a friendlier alternative to netstat. Output is shown as an easy-to-read table that can be filtered and sorted, and it can also be produced as JSON or in a custom format. It is released under the MIT license.

The README highlights that a common command such as netstat -tulpn can be replaced by a shorter somo -l. It also allows interactively killing processes that hold a port, which is handy when a development server is stuck. Most of the time it should be run with elevated privileges so it can see all processes and ports.

It installs with cargo from crates.io, and the project notes that the master branch may contain unreleased features, so the crates.io page is the reference for the stable version. Somo suits developers and system administrators who regularly check which processes are listening on which ports.

Key features

  • Readable table view of sockets and ports
  • Filtering and sorting of results
  • Interactive process killing
  • JSON and custom output formats
  • Linux and macOS support
  • Shorter commands than netstat

Pricing: Free and open source under the MIT license.

Socket alternatives: questions

What is the best open-source alternative to Socket?
Trivy is the top-ranked open-source alternative to Socket on Enlisted: A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes. Other strong options are Grype, Dependency-Track and Somo.
Are these Socket alternatives free?
All 4 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of Socket alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all