
Grype
Grype is a free open-source vulnerability scanner from Anchore used to find known flaws in container images, filesystems, and SBOMs for DevSecOps teams.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
What it is
A command-line tool that reads the packages inside an image or directory, matches them against a vulnerability database, and lists the issues it finds. It covers OS packages from Alpine, Debian, Ubuntu, RHEL, and others, plus language packages from Java to Rust.
What it helps with
- Scanning Docker, OCI, and Singularity images in CI
- Ranking findings with EPSS, KEV, and a risk score
- Filtering or adding context to results with OpenVEX
- Checking an existing SBOM without the original image
Who it's for
DevSecOps and platform engineers checking the software they build and ship.
Worth knowing
Pick Grype when you want a lean scanner that does only vulnerability matching and risk ranking. Trivy is the better pick when one tool should also catch misconfigurations, secrets, and licenses.
Does it scan local container storage?
Yes, on Linux it can scan images straight from a local containers-storage store.
Is commercial support available?
Yes, Anchore offers commercial support for Grype.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.