Skip to content

grype

Vulnerability Scanning

A vulnerability scanner for container images, filesystems, and SBOMs.

Go Latest v0.116.0 · 10d ago Security brief →

Features

  • Scan container images, filesystems, and SBOMs for known vulnerabilities
  • Support major OS package ecosystems (Alpine, Debian, Ubuntu, RHEL, Oracle Linux, Amazon Linux, etc.)
  • Support language‑specific packages (Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, …)
  • Threat and risk prioritization with EPSS, KEV, and custom risk scoring

Recent releases

View all 16 releases →
No immediate action
v0.116.0 Mixed

RHEL dupes, Chainguard, Arch pop, Reachability, Dedup, ESM

Upgrade now
v0.115.0 Breaking risk
Dependencies Breaking upgrade

Go vulns, GHSA merge, bug fixes, dependency bumps

No immediate action
v0.114.0 New feature

zarf package scanning

Monitor
v0.113.0 New feature
Crypto / TLS

Ubuntu 26.04 + Hummingbird filter + TLS/HTTP warnings

v0.112.0 New feature
Notable features
  • Ignore rules expanded to owned sub packages of distro packages
Full changelog

Added Features

  • Expand ignore rules to owned sub packages of distro packages [#3368 #3326 @kzantow]

Additional Changes

  • update anchore dependencies [#3391 @anchore-oss-update-bot]

(Full Changelog)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
12,594
Forks
830
Languages
Go Go Template Shell

Install & Platforms

Install via
shell-script brew docker chocolatey macports

Beta — feedback welcome: [email protected]