Grype Container and SBOM Vulnerability Scanner
Scan container images, filesystems, and SBOMs for known vulnerabilities using Anchore Grype. Supports major OS package ecosystems and language-specific packages with EPSS risk scoring and OpenVEX filtering.
Installation
Requirements and caveats from upstream:
- Supports language-specific packages (Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, and more)
- Supports Docker, OCI, and Singularity image formats
- See Installation docs for more ways to get Grype, including Homebrew, Docker, Chocolatey, MacPorts, and more!
Basic usage or getting-started notes:
New to Grype? Check out the Getting Started guide for a walkthrough!
The quickest way to get up and going:
bash
Source: https://github.com/anchore/grype
Extracted from upstream docs: https://raw.githubusercontent.com/anchore/grype/HEAD/README.md