Home / Grype

Open source vulnerability scanner

Grype by Anchore

An easy-to-integrate open source vulnerability scanning tool for containers, source code project directories, and filesystems.

Use Grype, our CLI tool, to generate a list of known vulnerabilities from containers, source code project directories, and filesystems.


Scan OS and language-specific packages

Grype is a CLI tool that scans container images, local directories, and filesystems for known vulnerabilities. It supports major OS package ecosystems (including Alpine, Debian, Ubuntu, and RHEL) alongside language-specific dependencies (such as Java, JavaScript, Python, Go, and Rust). Grype runs entirely locally without requiring external services. You can execute a scan simply by pointing the CLI at a target, such as a container image (grype alpine:latest) or a project directory (grype ./my-project). Findings are output as a human-readable table or as a JSON report for further processing.

Full list of output formats >


View prioritized results across vulnerability sources

Grype goes beyond basic severity scoring by incorporating risk-based signals to help teams focus on what matters most. In addition to CVSS, Grype’s risk-based prioritization engine incorporates EPSS (Exploit Prediction Scoring System) and data from CISA’s Known Exploited Vulnerabilities (KEV) catalog into its report generation, to highlight the vulnerabilities in your system that carry the highest risk. This helps reduce noise and prioritize remediation efforts based on real-world risk, not just severity. To further assist with triage, use the “explain” functionality of Grype to gain insight into why a specific vulnerability was flagged. It outputs identifiers and locations of the vulnerable software, references to relevant security advisories, and details about the match criteria that was used to surface the finding.


Automate scans in your CI/CD pipeline

Grype is built for automation, making it straightforward to embed vulnerability scanning into CI/CD workflows. You can integrate Grype into your CI/CD automated build processes using the CLI directly, or by using the Anchore Container Scan Action if you use GitHub Actions, to automatically scan code or container images on every commit. Pipelines can be configured to fail automatically based on specific severity thresholds, preventing insecure software from progressing.


Combine with Syft for separate SBOM generation

Syft and Grype are designed to work together for more efficient, ongoing vulnerability scanning. Syft first generates an SBOM, creating a complete inventory of all packages in containers, source code project directories, and filesystems. With an SBOM that represents a static set of software, Grype can then perform its entire security scanning pass without the need to re-analyze the original material, using only the SBOM as input. In addition to Syft’s native output, Grype natively supports scanning standard SBOM formats like SPDX and CycloneDX, providing flexibility when consuming vendor-supplied SBOMs.

Learn more about Syft >


Save 75% more time with automated vulnerability management

Anchore Enterprise builds on Grype’s open source vulnerability scanning technology to integrate with CI/CD pipelines, automate SBOM generation, support on-premises and air-gapped deployments, and more.

See how DreamFactory saved time with Anchore Enterprise. 

Get up and running
in minutes.

Tutorials and documentation for easy implementation.
Tutorials and documentation for easy implementation.

Open source foundation, enterprise-ready.

Anchore Enterprise builds on open source Syft and Grype to deliver a continuous compliance and security solution built for the needs of enterprises and government agencies. Secure development pipelines across multiple teams and toolchains. Provide security teams with the visibility and policy controls they need to ensure compliance.
Explore our Platform

Grype Frequently Asked Questions (FAQs)

Chevron icon Is Grype safe to use?

Yes. From a data privacy and security standpoint, Grype is completely safe to use. Grype runs entirely locally and doesn’t require any online services to operate — the only network activity is downloading the vulnerability database and any of the software material you have access to and would like to scan. After that initial download, scanning works fully offline. Grype and the system that prepares the Grype Database (Vunnel) are also fully open source under the Apache 2.0 license, meaning their vulnerability-matching logic and database pipeline are completely transparent and auditable by anyone.

Chevron icon What is the difference between Grype and Syft?

Grype and Syft are two of Anchore’s open source tools, alongside Grant. While they can be used in tandem for a more complete software supply chain security workflow, each serves a distinct purpose and can be run independently. Syft generates comprehensive software bills of materials (SBOMs). Grype is a vulnerability scanner that identifies and prioritizes known vulnerabilities from an SBOM, container image, or project directory. Grant is a license inspection and compliance tool that provides insights, categorizations, and light-weight compliance enforcement against software licenses in your SBOMs.

Chevron icon How does Grype compare to other vulnerability scanners?

Grype is an open-source container vulnerability scanner maintained by Anchore and developed by Anchore OSS and its vibrant open-source contributor community. It’s designed for accurate vulnerability detection in containers, source code project directories, and filesystems. Unlike broader security tools, Grype is focused specifically on vulnerability scanning, with an SBOM-first approach that enables continuous re-evaluation as new vulnerabilities are disclosed and risk-based prioritization to help teams focus on the highest risk findings within their own environments.

For organizations operating at scale, Anchore Enterprise provides a complete software supply chain security platform featuring centralized visibility, continuous compliance monitoring, and robust policy enforcement. To power these advanced capabilities, Anchore Enterprise leverages Syft and Grype’s best-in-class software inspection and vulnerability scanning technology.

Chevron icon What can Grype scan for vulnerabilities?

Grype can scan SBOMs from containers, source code project directories, filesystems, and more.

Chevron icon What types of packages, ecosystems, and image formats does Grype support?

Grype supports vulnerability scanning for Linux distributions, application dependencies, and software artifacts across more than 30 package ecosystems, including Java, JavaScript, Python, Go, .NET, Ruby, Rust, PHP, Alpine, Debian, Red Hat, SBOMs, GitHub Actions, Terraform, AI models, and more. For a more detailed list and the most recent updates, visit our Docs site: https://oss.anchore.com/docs/capabilities/ 

Chevron icon Does Grype support VEX?

Yes, Grype supports OpenVEX and CSAF VEX, allowing teams to filter and assess vulnerability results by supplying additional custom context. By applying custom assessments with VEX, practitioners use Grype to further refine their vulnerability reports as part of their risk-based prioritization efforts, helping to reduce noise and focus attention.

Join our live stream every Thursday.

Join the Anchore Open Source team to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools.

Speak with our security experts

Learn how Anchore’s SBOM-powered platform can help secure your software supply chain.