Cubbie Conference December 10, 2026 in San Francisco Get tickets →

Sigstore vs Trivy

Sigstore logo
SigstoreSupply Chain Security
FreePublished price
Trivy logo
TrivyContainer Security
Free (open source)Published price
Sigstore logo
Sigstore
Supply Chain Security

sign. verify. protect. Make sure your software is what it claims to be.

Trivy logo
Trivy
Container Security

Open-source security scanner.

Overview
CategorySupply Chain SecurityContainer Security
What it isOpen-source project providing free code signing and verification infrastructure for software supply chain integrity and provenance.Trivy by Aqua Security is an open-source comprehensive vulnerability scanner for containers, filesystems, Git repositories, and Kubernetes configurations.
Pricing
Published priceFree
Sigstore is a free, open-source project under the OpenSSF (Linux Foundation) with no paid tier. Its public-good signing infrastructure (Fulcio, Rekor, cosign) is free to use; ther…
Free (open source)
Trivy is fully open source under Apache 2.0 with no paid tier, usage limits, or premium features in the tool itself. Aqua Security (the maintainer) monetizes a separate enterprise…
Pricing modelNot availableFree
Free optionsFree plan · No free trialFree plan · No free trial
Deal on CubbieNone right nowNone right now
Company
Founded20212019
Team size11-50 employees11-50 employees
HeadquartersMountain View, CASan Francisco, California
Featured clientsNot availableDeveloper teams globally

Buyers also compare

Hot in AI

Rising

CRM

Field Service Management

Project Management

Email Marketing

Cloud Hosting

Email Deliverability