12,967 stars · Apache-2.0 (read from /blob/main/LICENSE; plain and unmodified, and the appendix is the unfilled [yyyy] [name of copyright owner] template, so no holder is named) · v0.120.0 (2026-10-02, year confirmed by pkg.go.dev; marked an immutable release) · Track this in Scout
Lists published security holes found in a container image, a folder, or a parts list of software.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Grype is a single command-line program written in Go. It identifies every piece of software inside whatever you point it at, then matches each piece against public vulnerability databases and prints what it finds, with a severity for each.
What it is good for. Anyone who built a container six months ago and has not thought about it since. The holes were not there when you built it. They were published afterwards, in libraries you never chose directly. This is how you find out, in one command, without signing up for anything.
- Two minutes from nothing to a useful answer, and it only reads. You can run it against an image you already use with no setup and no risk.
- It takes a container image, a plain folder of files, or a parts list produced by another tool, so it fits whether or not you already track what your software is made of.
- Plain Apache-2.0, read from the licence file. The company behind it sells other products, and this one carries no commercial condition at all. Released on 2 October 2026, with code moving the same day.
- It downloads a large vulnerability database and refreshes it, so it needs network access. Offline it either fails or quietly uses stale data, which is worse.
- ⚠ 329 waiting problems and a very fast release pace at version 0.120. Pin the version if you want the same output tomorrow as today.
- It prints a list of identifiers and severities. Knowing which ones genuinely reach your code, and which are in a part you never call, is security knowledge the tool does not supply. Nothing is fixed for you.
- aquasecurity/trivy
The same scanning of images and folders and by far the most widely used; the difference is scope, because it also checks configuration mistakes, leaked secrets and cloud settings.
Track this in Scout - quay/clair
The same static analysis of container images, but built to run as a service that indexes and matches continuously rather than a single command you type.
Track this in Scout - future-architect/vuls
The same reporting of known holes, but aimed at running Linux and FreeBSD machines and network devices rather than at images, and GPL-3.0 rather than permissive.
Track this in Scout
curl -sSfL https://get.anchore.io/grype | sudo sh -s -- -b /usr/local/bin

