
Grype is a vulnerability scanner for container images and filesystems that scans for known vulnerabilities and supports various image formats.

Grype is a vulnerability scanner for container images and filesystems that scans for known vulnerabilities and supports various image formats.
Grype is a Container Security product. It is deployed as on-premises software. Pricing is free.
Grype is an open-source vulnerability scanner developed by Anchore that scans container images, filesystems, and Software Bill of Materials (SBOMs) for known security vulnerabilities. Scan Targets: - Container images (Docker, OCI, and Singularity image formats) - Local filesystems and directories - SBOMs (including those generated by Syft) OS Package Ecosystem Support: - Alpine, Debian, Ubuntu, RHEL, Oracle Linux, Amazon Linux, and others Language-Specific Package Support: - Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, and others Grype cross-references discovered packages against vulnerability databases to identify known CVEs and security issues. It supports threat and risk prioritization using EPSS (Exploit Prediction Scoring System), KEV (Known Exploited Vulnerabilities), and risk scoring to help users understand and prioritize remediation efforts. The tool also supports OpenVEX, which allows users to filter and augment scan results based on Vulnerability Exploitability eXchange data. Grype can accept SBOM input directly, either as a file or via stdin pipe, enabling faster vulnerability detection workflows. It is installable via curl, Homebrew, Docker, Chocolatey, MacPorts, and other package managers. Grype is released under the Apache-2.0 License and is sponsored by Anchore. Commercial support options are available through Anchore.
Common questions about Grype including features, pricing, alternatives, and user reviews.
Grype is Grype is a vulnerability scanner for container images and filesystems that scans for known vulnerabilities and supports various image formats. It is a Cloud Security solution designed to help security teams with SBOM.
Grype is deployed as a on-premises solution, suited to startup, smb, mid-market, enterprise organizations looking to operationalize cloud security. The free tier is well-suited to evaluation, small teams, and learning environments.
Grype is built for security teams handling SBOM. Teams typically adopt Grype when they need to cloud security capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/grype
Grype is a free Cloud Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/anchore/grype/ for download and installation instructions.
Popular alternatives to Grype include:
Compare all Grype alternatives at https://cybersectools.com/alternatives/grype
Grype is for security teams and organizations that need SBOM. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Cloud Security tools can be found at https://cybersectools.com/categories/cloud-security
Head-to-head feature, pricing, and rating breakdowns.
Container security platform scanning images, enforcing K8s policies & runtime threats
Secure container images with minimal CVEs, FIPS validation, and STIG hardening
Healthcare-focused software security platform for vulnerability reduction
Container scanning, profiling & vulnerability mgmt with runtime-aware insights