OSS Tanbou

scan container images, filesystems, and SBOMs against vulnerability data and prioritize findings with EPSS, KEV, and VEX

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
12,968
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 2, 2026
On this page

Overview

Grype is a CLI vulnerability scanner for container images, filesystems, and SBOMs. It identifies operating-system and language packages, matches them against vulnerability data, and provides EPSS, KEV, risk scoring, and OpenVEX context to help prioritize findings.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Scan container images, directories, and SBOMs with one CLI

Grype accepts Docker/OCI images, local filesystems, and SBOM inputs such as Syft output and matches the package inventory against vulnerability data.

Sources: [1]

Cover both OS packages and language dependencies

It supports major Linux package ecosystems plus application packages for Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, and more.

Sources: [1]

Prioritize findings with EPSS, KEV, risk scores, and OpenVEX

Beyond severity, Grype can use exploitation-probability and known-exploited data and can apply OpenVEX context such as not-affected status.

Sources: [1]

Best fit

Fits CI/CD pipelines that need vulnerability checks for images and artifacts

Build outputs, source trees, and SBOMs can be scanned in pipelines and the findings reviewed or gated according to project policy.

Sources: [1]

Before adoption

Treat vulnerability-database freshness as part of the scan result

Grype uses a local vulnerability database and has auto-update enabled by default in its database options. Offline or update-disabled environments should make db update/status an explicit pipeline step.

Sources: [3]

Triage false positives and package mappings with VEX and deployment context

The v0.120.0 release includes fixes for CPE-related false positives. A scanner match is not automatically proof of exploitability, so package provenance, fixed versions, VEX, and actual exposure should be considered.

Sources: [2][1]

v0.120.0 moves release-checksum signing to Sigstore bundles

The release changes checksum signing to a Sigstore bundle, and the installer supports a pinned tag plus checksum validation. CI should pin the scanner version for reproducibility.

Sources: [2][4]

Official sources

  1. [1]Grype README(2026-10-03)
  2. [2]Grype v0.120.0 release(2026-10-03)
  3. [3]Grype database options(2026-10-03)
  4. [4]Grype v0.120.0 install script(2026-10-03)
  5. [5]Grype Apache-2.0 license(2026-10-03)
Supplemental curator note

Grype can scan container images, repository directories, and Syft SBOMs through one CLI, which makes it practical for CI vulnerability gates. Results still depend on vulnerability-data freshness and package identification, so severity alone should not be an automatic release decision without VEX and deployment context.

Try it in 3 steps

  1. 1

    Install v0.120.0 with an explicit version

    Pass the tag to the official installer and pin the scanner version in CI for reproducibility.

    curl -sSfL https://get.anchore.io/grype | sudo sh -s -- -b /usr/local/bin v0.120.0
  2. 2

    Update and inspect the vulnerability database

    Verify database freshness before using scan output for security decisions.

    grype db update && grype db status
  3. 3

    Scan a container image

    Triage findings using fixed versions, EPSS/KEV, package provenance, and VEX rather than severity alone.

    grype alpine:latest
Check the official README

Growth

Growth trends · Last 30 days

12,968 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
46
Open PRs
84

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • containers
  • security
  • vulnerability
  • docker
  • golang
  • go
  • static-analysis
  • container-image
  • tool
  • oci
  • cyclonedx
  • vulnerabilities
Stars
12,968
Forks
896
Watchers
82
Open issues
334
Contributors
152
Owner type
Organization
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 2, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?