Ross ROSS = Recommend OSS · open-source software intelligence for agents

anchore/grype

A vulnerability scanner for container images and filesystems observed · 2026-08-28

github.com/anchore/grype · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 97
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 9
  • age_days: 2290
  • days_rel: 23
  • days_push: 7
  • n_releases_24m: 60

Full methodology

Adoption not part of the score

12789 stars · 868 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Grype is an open-source vulnerability scanner for container images, filesystems, and SBOMs, written in Go by Anchore. It identifies known CVEs across OS and language package ecosystems and supports risk prioritization via EPSS, KEV, and OpenVEX filtering.

Use cases

  • scan docker images for known vulnerabilities
  • find CVEs in a container image before deploying
  • scan a filesystem or SBOM for vulnerable packages
  • check if my dependencies have security vulnerabilities
  • prioritize vulnerabilities with EPSS and KEV data
  • integrate vulnerability scanning into CI/CD pipeline
  • generate vulnerability reports for OCI images

When to choose

  • you need fast, local vulnerability scanning of container images or filesystems
  • you want SBOM-based scanning with CycloneDX or Syft integration
  • you need OpenVEX support for filtering false positives
  • you want a free CLI alternative to commercial container scanners

When to avoid

  • you need full runtime container security monitoring rather than static scanning
  • you require a managed scanning service with a dashboard and policy enforcement
  • you need binary-level analysis of proprietary executables without package metadata

Facets

cli-tool · maturity active

vulnerability-scanning security cli developer-tools security developer-tools windows cli go sbom cve container-security openvex cyclonedx static-analysis anchore containers devops linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
anchore/grypemain98

For agents

markdown · JSON · MCP: product_card(name="anchore/grype")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem