7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Grype

Open source

Command-line vulnerability scanner that checks container images, filesystems and SBOMs for known security issues in OS and language packages.

GitHub stars
13k
Last commit
today
Repository age
6 years
Version
v0.120.0
Licence
Apache-2.0
Self-hosted
Yes

About Grype

Grype is an open-source vulnerability scanner for container images and filesystems. You point it at an image, a directory or a software bill of materials (SBOM), and it reports known vulnerabilities in the packages it finds, so teams can catch risky dependencies before software ships.

It covers major operating system package ecosystems such as Alpine, Debian, Ubuntu, RHEL, Oracle Linux and Amazon Linux, as well as language packages for Ruby, Java, JavaScript, Python, .NET, Go, PHP and Rust. Docker, OCI and Singularity image formats are supported. Results can be prioritized with EPSS, KEV and risk scoring, and OpenVEX documents can filter or augment findings.

Grype is written in Go and released under the Apache-2.0 license. It can be installed through Homebrew, Docker, Chocolatey, MacPorts and other routes, and the documentation includes a getting started guide, CLI reference and configuration reference. Development is sponsored by Anchore, which also handles commercial support requests for Grype and its companion tool Syft.

Key features

  • Scans container images, filesystems and SBOMs
  • OS package support for Alpine, Debian, Ubuntu, RHEL
  • Language package support including Python, Go, Java
  • Docker, OCI and Singularity image formats
  • EPSS, KEV and risk-score prioritization
  • OpenVEX filtering of scan results

Good fit for

  • →Scanning images in CI pipelines
  • →Checking SBOMs for known vulnerabilities
Built with
Go
Docker
Tags
vulnerability-scanner
containers
security
sbom
devsecops
cli
go

Grype: questions and answers

What is Grype used for?
Grype is a command-line vulnerability scanner that checks container images, filesystems and SBOMs for known security issues in OS and language packages. It is a good fit for scanning images in CI pipelines and checking SBOMs for known vulnerabilities.
Is Grype open source?
Yes. Grype is open source under the Apache-2.0 licence. Its source code is on GitHub at anchore/grype and is written mainly in Go.
Is Grype free?
Yes. Grype is open source, so the software itself is free to use.
What is Grype an alternative to?
Grype is an open-source alternative to Snyk, Wiz, Aikido Security and Socket. Other open-source alternatives to Snyk include Trivy, Dependency-Track and Horusec.
Is Grype actively maintained?
Yes. The most recent commit to Grype was on 2 October 2026, and the latest release is v0.120.0, published on 2 October 2026. The project has 13k stars on GitHub.

Open-source alternatives to Grype

See all

SaaS alternatives to Grype

See all