Grype logo

Grype

Open source · SBOM analysis

Grype scans container images and filesystems for known vulnerabilities. It pairs with Syft, which produces the SBOM Grype can then assess, so the two together cover generation and vulnerability matching from the command line or a pipeline.

Key facts

VendorAnchore
LicenceApache-2.0
Latest releasev0.119.0, 17 Sept 2026
Repository since2020
DoesVulnerability matching
ReadsContainer images, Filesystems
Websitegithub.com/anchore/grype
Sourcegithub.com/anchore/grype

Sources

Checked 21 Sept 2026. Spotted something out of date? Tell us.

Other SBOM analysis tools

Need the product tested as well? See Cyber Resilience Act compliance testing providers.