Skip to content

grype

v0.116.0 Feature

This release adds 6 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

container-image containers cyclonedx docker go openvex
+5 more
security static-analysis vex vulnerabilities vulnerability

Summary

AI summary

Broad release touches Bug Fixes, Added Features, https://github.com/anchore/grype/pull/3509, and https://github.com/anchore/grype/pull/3542.

Changes in this release

Feature Medium

Duplicate RHSAs to all applicable RHEL minor versions.

Duplicate RHSAs to all applicable RHEL minor versions.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Add Chainguard OSV transformer.

Add Chainguard OSV transformer.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Populate package architecture for matching.

Populate package architecture for matching.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Add lightweight reachability analysis to reduce Golang false positives.

Add lightweight reachability analysis to reduce Golang false positives.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Deduplicate Go matches that are aliases of each other.

Deduplicate Go matches that are aliases of each other.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Support Ubuntu ESM.

Support Ubuntu ESM.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Regenerate v6.1.8 blob and SQL schemas.

Regenerate v6.1.8 blob and SQL schemas.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Fix RHEL version streams handling.

Fix RHEL version streams handling.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Ensure Grype matches u-boot in SBOM when type is firmware.

Ensure Grype matches u-boot in SBOM when type is firmware.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Ignore Go compiler‑affecting CVE when Docker image only contains a binary compiled with Go.

Ignore Go compiler‑affecting CVE when Docker image only contains a binary compiled with Go.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Low

Emit warnings for consistently unreadable files (non‑SBOMs) during Zarf scans.

Emit warnings for consistently unreadable files (non‑SBOMs) during Zarf scans.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Fail parsing GitHub Actions workflows correctly.

Fail parsing GitHub Actions workflows correctly.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Prevent Go vulnerability reporting when installed version exceeds fixed version.

Prevent Go vulnerability reporting when installed version exceeds fixed version.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Full changelog

Added Features

  • duplicate RHSAs to all applicable RHEL minor versions [PR #3542 @willmurphyscode]
  • add chainguard osv transformer [PR #3474 @crosleyzack]
  • populate package architecture for matching [PR #3504 @willmurphyscode]
  • lightweight reachability analysis to reduce Golang false positives [Issue #2960] [PR #3509 @spiffcs]
  • Deduplicate Go matches that are aliases of each other (same CVE reported under both a govulndb GO-* ID and its GHSA) [Issue #3511] [PR #3509 @spiffcs]
  • Support Ubuntu ESM [Issue #3544] [PR #3546 @wagoodman]

Bug Fixes

  • regenerate v6.1.8 blob and sql schemas [PR #3574 @spiffcs]
  • rhel version streams [PR #3572 @kzantow]
  • Grype doesn't match u-boot in SBOM if type is set to firmware [Issue #2537]
  • Ignore Go compiler affecting CVE when Docker image only contains a binary compiled with Go [Issue #1782]
  • Zarf scans emit warnings for consistently unreadable files (i.e., included non-SBOMs) [Issue #3516] [PR #3545 @brandtkeller]
  • Fail parsing github actions [Issue #3220]
  • Go vulnerability returned when installed version is greater than fixed version [Issue #3520]

Dependencies

14 dependency changes (11 updated, 3 added).

Updated (11 packages)
  • github.com/anchore/go-rpmdb v0.1.0v0.2.0
  • github.com/anchore/syft v1.46.0v1.48.0
  • github.com/klauspost/compress v1.18.6v1.19.0
  • golang.org/x/text v0.38.0v0.39.0
  • golang.org/x/tools v0.46.0v0.47.0
  • gorm.io/gorm v1.31.1v1.31.2
  • modernc.org/cc/v4 v4.28.2v4.28.4
  • modernc.org/ccgo/v4 v4.34.0v4.34.4
  • modernc.org/gc/v3 v3.1.2v3.1.3
  • modernc.org/libc v1.72.3v1.73.4
  • modernc.org/sqlite v1.51.0v1.53.0
Added (3 packages)
  • github.com/mattn/go-sqlite3 v1.14.23
  • gorm.io/driver/sqlite v1.6.0
  • howett.net/plist v1.0.1

(Full Changelog)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track grype

Get notified when new releases ship.

Sign up free

About grype

A vulnerability scanner for container images and filesystems

All releases →

Beta — feedback welcome: [email protected]