← Back to home
Comparison · Infra & APIs

Lima vs Greenbone Vulnerability Manager

A side-by-side editorial comparison of Lima and Greenbone Vulnerability Manager — release velocity, themes, recent moves, and the top alternatives to consider.

Lima vs Greenbone Vulnerability Manager: at a glance

FeatureLimaGreenbone Vulnerability Manager
SectorInfra & APIsInfra & APIs
Velocity score2.56.3
Sparks · 30d01
Top themeslocal virtualization, guest os support, windows guests, agent sandboxingvulnerability management, web application scanning, gmp protocol, report modeling
Last editorial update3h ago3h ago
WebsiteVisit →Visit →

What is Lima?

Lima keeps adding guest operating systems, and a flag to stop AI agents wrecking the host.

Lima's release stream is a steady widening of what it can boot. The 2.1 line added experimental macOS and FreeBSD guests and a limactl shell --sync flag intended to keep AI agents from breaking host files; the 2.2 betas add experimental Windows Server 2025 and Windows 11 guests, TPM emulation under QEMU, a limactl screenshot command, and an option to turn off password-less sudo. Between those, the tags are CLI fixes and template maintenance.

Read the full Lima trajectory →

What is Greenbone Vulnerability Manager?

Greenbone's scanner daemon is growing a web-application scanning class beside its network roots.

gvmd releases every week or two, and the changelog splits cleanly in three: a sustained build-out of web application scanning, a rewrite of how reports are modeled and exported, and a long tail of memory-management fixes in the C core. Recent versions added web application scanner preferences, scanner verification, and a Web Application VT subtype with a database migration. The report work moved from ad-hoc XML toward a structured report model addressable through new GMP commands.

Read the full Greenbone Vulnerability Manager trajectory →

Lima vs Greenbone Vulnerability Manager: editorial side-by-side

L
Lima
INFRA · APIS
2.5

Lima keeps adding guest operating systems, and a flag to stop AI agents wrecking the host.

◆ Current state

Lima's release stream is a steady widening of what it can boot. The 2.1 line added experimental macOS and FreeBSD guests and a limactl shell --sync flag intended to keep AI agents from breaking host files; the 2.2 betas add experimental Windows Server 2025 and Windows 11 guests, TPM emulation under QEMU, a limactl screenshot command, and an option to turn off password-less sudo. Between those, the tags are CLI fixes and template maintenance.

◆ Where it's heading

A tool that began as Linux VMs on macOS is becoming a general local virtualization front end, with macOS, FreeBSD, and Windows guests all arriving inside two release lines and much of it contributed through mentorship programs. A second thread is tightening the host boundary, with the sync flag, the sudo opt-out, and TPM emulation all narrowing what a guest can assume or reach. Everything guest-related is still marked experimental.

◆ Prediction

Each guest platform has arrived experimental and then accumulated follow-up pull requests; Windows support is at that stage now, so the next releases most likely stabilize it rather than add another operating system.

G6.3

Greenbone's scanner daemon is growing a web-application scanning class beside its network roots.

◆ Current state

gvmd releases every week or two, and the changelog splits cleanly in three: a sustained build-out of web application scanning, a rewrite of how reports are modeled and exported, and a long tail of memory-management fixes in the C core. Recent versions added web application scanner preferences, scanner verification, and a Web Application VT subtype with a database migration. The report work moved from ad-hoc XML toward a structured report model addressable through new GMP commands.

◆ Where it's heading

Greenbone is widening what gvmd can orchestrate. Network and container scanning were the existing surface; web application scanning is being brought to parity, with its own VT class, preferences, validation, and verification path. In parallel the GMP protocol is gaining first-class report retrieval commands, which makes report data consumable by tooling rather than only renderable. The bug-fix stream is dominated by frees and cleanup in long-lived report paths, the signature of a codebase under memory pressure at scale.

◆ Prediction

Web Application VTs now have a subtype, a migration, and scanner verification, but the audit and scan report commands were added separately; expect the report model work to fold web application results into the same structured retrieval path rather than leaving a parallel one.

Alternatives to Lima and Greenbone Vulnerability Manager

Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Lima or Greenbone Vulnerability Manager.

See all Lima alternatives → · See all Greenbone Vulnerability Manager alternatives →

Recent activity from Lima and Greenbone Vulnerability Manager

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 5d agoGreenbone Vulnerability Manageropenvasd library bumped to 23.9
  2. 5d agoGreenbone Vulnerability ManagerGMP gains a get_audit_report_hosts command
  3. 10d agoGreenbone Vulnerability ManagerWeb Application VTs become a first-class scan type
  4. 18d agoGreenbone Vulnerability ManagerStructured report model and the get_scan_report command
  5. 19d agoGreenbone Vulnerability ManagerPer-object asset permissions and report-script trust checks
  6. 23d agoLima2.2.0-rc.0: Windows 11 guests and a sudo opt-out
  7. 24d agoGreenbone Vulnerability ManagerAggregate grouping and family-name fixes
  8. 1mo agoLima2.2.0-beta.0: Windows Server 2025 guests and TPM emulation
  9. 3mo agoLima2.1.2-beta.0: CLI mount and rsync path fixes
  10. 4mo agoLima2.1.0-rc.1: macOS and FreeBSD guests, plus an agent sync guard

Frequently asked questions

What is the difference between Lima and Greenbone Vulnerability Manager?

They serve adjacent needs but don't currently overlap on shipped themes. Greenbone Vulnerability Manager is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Lima better than Greenbone Vulnerability Manager?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Greenbone Vulnerability Manager is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.

What are the best alternatives to Lima?

Top Lima alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Lima alternatives" section above for the current picks, or visit /alternatives/lima for the full list with editorial commentary on each.

What are the best alternatives to Greenbone Vulnerability Manager?

Top Greenbone Vulnerability Manager alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Greenbone Vulnerability Manager alternatives" section above for the current picks, or visit /alternatives/greenbone-gvmd for the full list with editorial commentary on each.