grype
Vulnerability ScanningA vulnerability scanner for container images, filesystems, and SBOMs.
Features
- Scan container images, filesystems, and SBOMs for known vulnerabilities
- Support major OS package ecosystems (Alpine, Debian, Ubuntu, RHEL, Oracle Linux, Amazon Linux, etc.)
- Support language‑specific packages (Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, …)
- Threat and risk prioritization with EPSS, KEV, and custom risk scoring
Recent releases
View all 16 releases →
Upgrade now
v0.115.0
Breaking risk
Dependencies
Breaking upgrade
Go vulns, GHSA merge, bug fixes, dependency bumps
Monitor
v0.113.0
New feature
Crypto / TLS
Ubuntu 26.04 + Hummingbird filter + TLS/HTTP warnings
v0.112.0
New feature
Notable features
- Ignore rules expanded to owned sub packages of distro packages
Full changelog
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Install & Platforms
Install via
shell-script
brew
docker
chocolatey
macports