On this page
Overview
Grype is a CLI vulnerability scanner for container images, filesystems, and SBOMs. It identifies operating-system and language packages, matches them against vulnerability data, and provides EPSS, KEV, risk scoring, and OpenVEX context to help prioritize findings.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Scan container images, directories, and SBOMs with one CLI
Grype accepts Docker/OCI images, local filesystems, and SBOM inputs such as Syft output and matches the package inventory against vulnerability data.
Sources: [1]
Cover both OS packages and language dependencies
It supports major Linux package ecosystems plus application packages for Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, and more.
Sources: [1]
Prioritize findings with EPSS, KEV, risk scores, and OpenVEX
Beyond severity, Grype can use exploitation-probability and known-exploited data and can apply OpenVEX context such as not-affected status.
Sources: [1]
Best fit
Fits CI/CD pipelines that need vulnerability checks for images and artifacts
Build outputs, source trees, and SBOMs can be scanned in pipelines and the findings reviewed or gated according to project policy.
Sources: [1]
Before adoption
Treat vulnerability-database freshness as part of the scan result
Grype uses a local vulnerability database and has auto-update enabled by default in its database options. Offline or update-disabled environments should make db update/status an explicit pipeline step.
Sources: [3]
Triage false positives and package mappings with VEX and deployment context
The v0.120.0 release includes fixes for CPE-related false positives. A scanner match is not automatically proof of exploitability, so package provenance, fixed versions, VEX, and actual exposure should be considered.
Official sources
- [1]Grype README(2026-10-03)
- [2]Grype v0.120.0 release(2026-10-03)
- [3]Grype database options(2026-10-03)
- [4]Grype v0.120.0 install script(2026-10-03)
- [5]Grype Apache-2.0 license(2026-10-03)
Supplemental curator note
Grype can scan container images, repository directories, and Syft SBOMs through one CLI, which makes it practical for CI vulnerability gates. Results still depend on vulnerability-data freshness and package identification, so severity alone should not be an automatic release decision without VEX and deployment context.
Try it in 3 steps
- 1
Install v0.120.0 with an explicit version
Pass the tag to the official installer and pin the scanner version in CI for reproducibility.
curl -sSfL https://get.anchore.io/grype | sudo sh -s -- -b /usr/local/bin v0.120.0 - 2
Update and inspect the vulnerability database
Verify database freshness before using scan output for security decisions.
grype db update && grype db status - 3
Scan a container image
Triage findings using fixed versions, EPSS/KEV, package provenance, and VEX rather than severity alone.
grype alpine:latest
Growth
Growth trends · Last 30 days
12,968 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 46
- Open PRs
- 84
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- containers
- security
- vulnerability
- docker
- golang
- go
- static-analysis
- container-image
- tool
- oci
- cyclonedx
- vulnerabilities
- Stars
- 12,968
- Forks
- 896
- Watchers
- 82
- Open issues
- 334
- Contributors
- 152
- Owner type
- Organization
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Oct 2, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Kyverno8,212 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Continuously apply policy as code through Kubernetes admission and background scans
Go - FlexPrice6,891 Stars
2 shared tag(s) · 1 shared category(s) · Same language
connect usage events to metering, pricing, credits, entitlements, subscriptions, and invoices in an Open Core billing stack
Go - SonarQube Community Build11,044 Stars
2 shared tag(s) · 1 shared category(s)
Continuously verify bugs, vulnerabilities, maintainability, and coverage with static analysis and Quality Gates in an open-source code-verification server
Java - legmacs42 Stars
2 shared tag(s) · 1 shared category(s)
Extend a small terminal editor with the same let-go Lisp and public APIs used by its built-in commands
Clojure - Moby72,143 Stars
2 shared tag(s) · Same language
the upstream project for assembling container engines and container-based systems
Go - LocalAI49,374 Stars
2 shared tag(s) · Same language
bring text, image, audio, and video runtimes into one control plane
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.