Grype
Open source · SBOM analysis
Grype scans container images and filesystems for known vulnerabilities. It pairs with Syft, which produces the SBOM Grype can then assess, so the two together cover generation and vulnerability matching from the command line or a pipeline.
Key facts
| Vendor | Anchore |
|---|---|
| Licence | Apache-2.0 |
| Latest release | v0.119.0, 17 Sept 2026 |
| Repository since | 2020 |
| Does | Vulnerability matching |
| Reads | Container images, Filesystems |
| Website | github.com/anchore/grype |
| Source | github.com/anchore/grype |
Sources
Checked 21 Sept 2026. Spotted something out of date? Tell us.
Other SBOM analysis tools
Need the product tested as well? See Cyber Resilience Act compliance testing providers.