Softwr
Grype logo

Grype

Vulnerability scanner for container images and filesystems

Overview

What Grype does

Grype is an open-source vulnerability scanner for container images and filesystems from Anchore. It pairs with Syft, Anchore’s software bill of materials generator: Syft catalogues what is in an image, Grype matches that inventory against vulnerability data. That separation is the design point. An SBOM produced once can be scanned repeatedly as new vulnerabilities are published, without re-analysing the image — which matters when the question is not "was this safe at build time" but "is it safe today".

What people use it for

  • Re-scanning stored SBOMs as new CVEs are published, without rebuilding images
  • Failing CI when a build introduces a known vulnerability
  • Auditing what is actually installed inside a third-party image

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Grype.

  • Depends on public vulnerability databases, so coverage and false positives vary by ecosystem
  • No triage, exception tracking or reporting UI — that is Anchore’s commercial product
  • Overlaps heavily with Trivy, and most teams pick one rather than running both

Cross-shopped

What people choose instead of Grype

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

  • Grype logo
    Grype
    vs
    Trivy logo
    Trivy

    Trivy: Broader scanning in one tool, including misconfiguration and secrets

  • Grype logo
    Grype
    vs
    Snyk logo
    Snyk

    Snyk: Commercial scanning with triage, fix pull requests and reporting

Pricing

What Grype costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Grype

Free

  • Full functionality
  • No usage limits
  • Community support

Capabilities

Features

  • Image and filesystem scanning

    Containers, directories and archives

  • SBOM-driven

    Scans a Syft SBOM directly, so inventory and matching are separate steps

  • Wide ecosystem coverage

    OS packages plus most major language dependency formats

  • Pipeline friendly

    Single binary with exit codes and machine-readable output

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Is Grype free?

Yes, open source from Anchore. Anchore Enterprise is the paid platform around it.

What is the difference between Grype and Syft?

Syft generates the software bill of materials; Grype matches that inventory against vulnerability data. They are designed to be used together.

Grype or Trivy?

They cover similar ground. Trivy is broader out of the box, including misconfiguration and secret scanning; Grype pairs more cleanly with an SBOM-first workflow.

Share

Keep looking

Where to go from Grype

Best Cybersecurity software for

Compare Grype with

Other Cybersecurity software

  • The world's most-loved password manager

  • Powerful protection against evolving threats

  • Simplify online life with LastPass password manager

  • Developer-first security platform

  • Open source password management for everyone

  • Drop-in user authentication and management for developers

  • Privacy-first VPN with one flat price and no email required to sign up

  • Enterprise AI governance and data compliance platform.

  • Secure, green and ad-free. Email to feel good about.

  • Runtime identity security at agentic scale

  • Secrets management for humans and AI agents

  • Customer identity and access management platform for SaaS applications

Softwr does not host reviews and shows no star rating for Grype, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Grype

Best Cybersecurity software alternatives

Open-source authentication and two-factor portal for reverse proxies

Headless identity and user management API

Open-source identity provider with flexible authentication flows

Open-source vulnerability and misconfiguration scanner

Secrets management for humans and AI agents

Security and AI agent governance for code and supply chain

Unified security platform automating vulnerability detection and fixing across development

Compare Grype with alternatives