Skip to content

grype

v0.114.0 Feature

This release adds 1 notable feature for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

container-image containers cyclonedx docker go openvex
+5 more
security static-analysis vex vulnerabilities vulnerability

Summary

AI summary

Added support for scanning zarf packages.

Changes in this release

Feature Low

Adds ability to scan zarf packages

Adds ability to scan zarf packages

Source: llm_adapter@2026-06-05

Confidence: high

Feature Low

Adds Govulndb OSV transformer implementation

Adds Govulndb OSV transformer implementation

Source: llm_adapter@2026-06-05

Confidence: high

Bugfix Medium

Respects withdrawn status of Go Vuln DB OSV records

Respects withdrawn status of Go Vuln DB OSV records

Source: llm_adapter@2026-06-05

Confidence: high

Full changelog

Added Features

  • Add ability to scan zarf packages [#3329 #3366 @brandtkeller]

Additional Changes

  • respect withdrawn status of Go Vuln DB OSV records [#3495 @willmurphyscode]
  • Govulndb OSV transformer [#3485 @willmurphyscode]

(Full Changelog)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track grype

Get notified when new releases ship.

Sign up free

About grype

A vulnerability scanner for container images and filesystems

All releases →

Beta — feedback welcome: [email protected]