Grype
apartment
3 companies hiring
Radar: Initial
Apache-2.0
Scans container images, filesystems and SBOMs for known vulnerabilities, reading OSV and other vulnerability sources.
SPDXOSV Schema
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| SPDX | scans |
|
| OSV Schema | scans |
Using this from an agent
- Interfaces
clicontainerci-action- Install
-
brew
grypegogithub.com/anchore/grype/cmd/grype - Invoke
grype sbom:<sbom.spdx.json> -o json- Consumes
- oci-image, spdx, cyclonedx, filesystem
- Emits
- json, sarif, table
- Runtime
- Needs network Non-deterministic Read-only No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Find known vulnerabilities in an artifact before it ships.
ci-pipelinecoding-agent
Re-scan an existing SBOM as new vulnerabilities are published, without rebuilding.
ci-pipeline
Results change over time for identical input — the vulnerability database moves. Never cache a verdict and treat it as still true.
- Website
- https://github.com/anchore/grype
- Repository
- https://github.com/anchore/grype
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-08-11
- Stars
- 12716 · last commit 2026-08-10
- Companies hiring
- 3 — distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.