{"repo":"anchore/grype","free":true,"listed":false,"github":"https://github.com/anchore/grype","clone":"git clone https://github.com/anchore/grype.git","description":"A vulnerability scanner for container images and filesystems","language":"Go","stars":12753,"topics":["containers","security","vulnerability","docker","golang","go","static-analysis","container-image","tool","oci"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Grype A vulnerability scanner for container images and filesystems. &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Features - Scan container images , filesystems , and SBOMs for known vulnerabilities (see the docs for a full list of supported scan targets) - Supports major OS package ecosystems (Alpine, Debian, Ubuntu, RHEL, Oracle Linux, Amazon Linux, and more) - Supports language-specific packages (Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, and more) - Supports Docker, OCI, and Singularity image formats - Threat & risk prioritization with EPSS , KEV , and risk scoring (see interpreting the results docs) - OpenVEX support for filtering and augmenting scan results [!TIP] New to Grype? Check out the Getting Started guide for a walkthrough! Installation The quickest way to get up and going: [!TIP] See Installation docs for more ways to get Grype, including Homebrew, Docker, Chocolatey, MacPorts, and more! The basics Scan a container image or directory for vulnerabilities: Scan an SBOM for even faster vulnerability detection: [!TIP] Check out the Getting Started guide to explore all of the capabilities and features. Want to know all of the ins-and-outs of Grype? Check out the CLI docs and configuration docs. Contributing We encourage users to help make these tools better by submitting issues when you find a bug or want a new feature. Check out our contributing overview and developer-specific documentation","default_branch":null,"files":null,"tree":[],"storefront":"/r/anchore","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/anchore/grype/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}