{"repo":"anchore/grype-db","free":true,"listed":false,"github":"https://github.com/anchore/grype-db","clone":"git clone https://github.com/anchore/grype-db.git","description":null,"language":"Python","stars":71,"topics":["grype","hacktoberfest","sqlite","vulnerability"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"grype-db Application to create a Grype vulnerability database from upstream vulnerability data sources. Installation Note : Currently, Grype-DB is built only for Linux and macOS. Recommended ... or, you can specify a release version and destination directory for the installation: [!IMPORTANT] You will require the zstd utility installed on your system to support the package command. Usage grype-db takes the following options: Pulling Data and Building the Database To pull data from a specific provider or providers and build the database in one step, run grype-db with the -g flag and specify providers with the -p flag: This example will build the database for the nvd provider. Multiple providers can be specified. If no providers are specified, grype-db defaults to all available providers as generated by vunnel list . However, note that that accessing GitHub provider data requires a token to authenticate to the GitHub API. See Getting Started Step-by-Step for more information on adding a GitHub token.) To download all provider data and build the vulnerability.db database, run: By default, grype-db will download provider data and build the database. To run these steps individually, use the build and pull subcommands. Pulling Provider Data To pull provider data without building the database: Omit the -p flag to target all available providers. Note that you can skip the pull step if you already have a local cache of vulnerability data, such as with make download-all-provider-cache ","default_branch":null,"files":null,"tree":[],"storefront":"/r/anchore","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/anchore/grype-db/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}