Skip to content

What is Grype?

Grype is a ci/cd tool. Grype scans container images for vulnerabilities. Feed it an image, get back a list of known CVEs—container security scanning that fits into build pipelines. The scanning is fast. The database updates regularly. Integration with CI is straightforward. Container security starts with knowing what vulnerabilities exist. Grype provides that visibility in builds. Key capabilities: Vulnerability scanning, Container images, SBOM support, CI/CD integration, Open source. Grype is free to use with no paid tier. Buyers most often compare Grype against Anchore, Aqua Security, Prisma Cloud.

TL;DR - Grype

  • Grype is an open-source vulnerability scanner for container images and filesystems
  • It scans for known vulnerabilities using multiple databases with fast results
  • Completely free and open-source
Pricing: Free forever
Best for: Individuals & startups

Pros & Cons

Pros

  • Open source vulnerability scanner
  • Container scanning
  • Fast
  • CI/CD integration
  • Active development

Cons

  • CLI only
  • Learning curve
  • Database updates needed
  • False positives possible
  • Enterprise features limited

Key Features

Vulnerability scanningContainer imagesSBOM supportCI/CD integrationOpen sourceAnchore

Pricing Plans

Open Source

Free

  • Full source code access
  • Apache License 2.0 license
  • Community support
  • Self-hosted
Grype scans container images for vulnerabilities. Feed it an image, get back a list of known CVEs—container security scanning that fits into build pipelines. The scanning is fast. The database updates regularly. Integration with CI is straightforward. Container security starts with knowing what vulnerabilities exist. Grype provides that visibility in builds.

Reviews

Be the first to review Grype

Your take helps the next buyer. Verified LinkedIn reviewers get a badge.

Write a review

Best Grype Alternatives

Top alternatives based on features, pricing, and user needs.

View full list →

Explore More

Grype FAQ

Is Grype free?

Grype is completely free and open source from Anchore. You can scan unlimited container images at no cost.

What is Grype?

Grype is a vulnerability scanner for container images and filesystems. It's fast, lightweight, and catches known CVEs in your dependencies.

Grype vs Trivy?

Both are excellent open source container scanners. Grype is from Anchore, Trivy from Aqua. Both work well, so try each and pick your preference.

Source: github.com