About Grype
Grype is an open-source vulnerability scanner for container images and filesystems. You point it at an image, a directory or a software bill of materials (SBOM), and it reports known vulnerabilities in the packages it finds, so teams can catch risky dependencies before software ships.
It covers major operating system package ecosystems such as Alpine, Debian, Ubuntu, RHEL, Oracle Linux and Amazon Linux, as well as language packages for Ruby, Java, JavaScript, Python, .NET, Go, PHP and Rust. Docker, OCI and Singularity image formats are supported. Results can be prioritized with EPSS, KEV and risk scoring, and OpenVEX documents can filter or augment findings.
Grype is written in Go and released under the Apache-2.0 license. It can be installed through Homebrew, Docker, Chocolatey, MacPorts and other routes, and the documentation includes a getting started guide, CLI reference and configuration reference. Development is sponsored by Anchore, which also handles commercial support requests for Grype and its companion tool Syft.
Key features
- Scans container images, filesystems and SBOMs
- OS package support for Alpine, Debian, Ubuntu, RHEL
- Language package support including Python, Go, Java
- Docker, OCI and Singularity image formats
- EPSS, KEV and risk-score prioritization
- OpenVEX filtering of scan results
Good fit for
- →Scanning images in CI pipelines
- →Checking SBOMs for known vulnerabilities
- Tags
- vulnerability-scanner
- containers
- security
- sbom
- devsecops
- cli
- go
Grype: questions and answers
- What is Grype used for?
- Grype is a command-line vulnerability scanner that checks container images, filesystems and SBOMs for known security issues in OS and language packages. It is a good fit for scanning images in CI pipelines and checking SBOMs for known vulnerabilities.
- Is Grype open source?
- Yes. Grype is open source under the Apache-2.0 licence. Its source code is on GitHub at anchore/grype and is written mainly in Go.
- Is Grype free?
- Yes. Grype is open source, so the software itself is free to use.
- What is Grype an alternative to?
- Grype is an open-source alternative to Snyk, Wiz, Aikido Security and Socket. Other open-source alternatives to Snyk include Trivy, Dependency-Track and Horusec.
- Is Grype actively maintained?
- Yes. The most recent commit to Grype was on 2 October 2026, and the latest release is v0.120.0, published on 2 October 2026. The project has 13k stars on GitHub.
Open-source alternatives to Grype
See all
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Kubescape
Security
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, an
Apache-2.0vs Wiz★ 12k
tfsec
Security
Tfsec is now part of Trivy
MITvs Aikido Security★ 7k
SaaS alternatives to Grype
See all
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaSWiz
Security
Agentless cloud security platform mapping risk across code, cloud and runtime
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Socket
Security
Supply chain security that detects risky open source packages before install
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaS
