Grype is a vulnerability scanner for container images and filesystems that works with various image formats and supports major operating system and language-specific packages. It can be integrated with CI tools like GitHub Actions and configured to use external data sources for enhanced vulnerability matching. Grype also supports various output formats and can be customized to include or exclude specific files or paths during scanning. Installation scripts are provided for macOS and Linux, and it also supports using SBOMs for faster vulnerability scanning.
Table of contents
FeaturesInstallationVerifying the artifactsGetting startedVEX SupportGrype's databaseShell completionPrivate Registry AuthenticationConfigurationFuture plansGrype Logo3 Comments
Sort: