Security and privacy · Edition No. 39 · 3 Oct 2026

anchore/grype

Lists published security holes found in a container image, a folder, or a parts list of software.

← Security and privacyRead the whole edition →

12,967 stars · Apache-2.0 (read from /blob/main/LICENSE; plain and unmodified, and the appendix is the unfilled [yyyy] [name of copyright owner] template, so no holder is named) · v0.120.0 (2026-10-02, year confirmed by pkg.go.dev; marked an immutable release) · Track this in Scout

Lists published security holes found in a container image, a folder, or a parts list of software.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Grype is a single command-line program written in Go. It identifies every piece of software inside whatever you point it at, then matches each piece against public vulnerability databases and prints what it finds, with a severity for each.

What it is good for. Anyone who built a container six months ago and has not thought about it since. The holes were not there when you built it. They were published afterwards, in libraries you never chose directly. This is how you find out, in one command, without signing up for anything.

Stars12,967
LicenceApache-2.0 (read from /blob/main/LICENSE; plain and unmodified, and the appendix is the unfilled [yyyy] [name of copyright owner] template, so no holder is named)
Latestv0.120.0 (2026-10-02, year confirmed by pkg.go.dev; marked an immutable release)
Good
  • Two minutes from nothing to a useful answer, and it only reads. You can run it against an image you already use with no setup and no risk.
  • It takes a container image, a plain folder of files, or a parts list produced by another tool, so it fits whether or not you already track what your software is made of.
  • Plain Apache-2.0, read from the licence file. The company behind it sells other products, and this one carries no commercial condition at all. Released on 2 October 2026, with code moving the same day.
Watch for
  • It downloads a large vulnerability database and refreshes it, so it needs network access. Offline it either fails or quietly uses stale data, which is worse.
  • ⚠ 329 waiting problems and a very fast release pace at version 0.120. Pin the version if you want the same output tomorrow as today.
  • It prints a list of identifiers and severities. Knowing which ones genuinely reach your code, and which are in a part you never call, is security knowledge the tool does not supply. Nothing is fixed for you.
Similar repositories
  • aquasecurity/trivy

    The same scanning of images and folders and by far the most widely used; the difference is scope, because it also checks configuration mistakes, leaked secrets and cloud settings.

    Track this in Scout
  • quay/clair

    The same static analysis of container images, but built to run as a service that indexes and matches continuously rather than a single command you type.

    Track this in Scout
  • future-architect/vuls

    The same reporting of known holes, but aimed at running Linux and FreeBSD machines and network devices rather than at images, and GPL-3.0 rather than permissive.

    Track this in Scout
Install
curl -sSfL https://get.anchore.io/grype | sudo sh -s -- -b /usr/local/bin
Screenshots
anchore/grype: GitHub preview cardanchore/grype: Screenshot 1

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.