
Vulnerability scanner for container images
Visit WebsiteWhat is Grype?
Grype is a ci/cd tool. Grype scans container images for vulnerabilities. Feed it an image, get back a list of known CVEs—container security scanning that fits into build pipelines. The scanning is fast. The database updates regularly. Integration with CI is straightforward. Container security starts with knowing what vulnerabilities exist. Grype provides that visibility in builds. Key capabilities: Vulnerability scanning, Container images, SBOM support, CI/CD integration, Open source. Grype is free to use with no paid tier. Buyers most often compare Grype against Anchore, Aqua Security, Prisma Cloud.
TL;DR - Grype
- Grype is an open-source vulnerability scanner for container images and filesystems
- It scans for known vulnerabilities using multiple databases with fast results
- Completely free and open-source
Pros & Cons
Pros
- Open source vulnerability scanner
- Container scanning
- Fast
- CI/CD integration
- Active development
Cons
- CLI only
- Learning curve
- Database updates needed
- False positives possible
- Enterprise features limited
Key Features
Pricing Plans
Open Source
Free
- Full source code access
- Apache License 2.0 license
- Community support
- Self-hosted
About Grype
LCLouis CorneloupReviews
Be the first to review Grype
Your take helps the next buyer. Verified LinkedIn reviewers get a badge.
Write a reviewBest Grype Alternatives
Top alternatives based on features, pricing, and user needs.
Explore More
Grype FAQ
Is Grype free?
What is Grype?
Grype vs Trivy?
Source: github.com