GRYPE
Container and filesystem vulnerability scanner by Anchore. Scans container images, SBOMs, and directories for known CVEs.
INSTALLATION#
curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh # Or: brew install grype
SCANNING#
# Container image grype nginx:latest grype python:3.11 grype myapp:v1.0 # From Docker daemon grype docker:mylocal-image # Filesystem grype dir:/path/to/project # SBOM (from Syft) grype sbom:sbom.json # Tar archive grype path/to/image.tar # OCI directory grype oci-dir:/path/to/oci
OUTPUT#
grype nginx -o table # Default table grype nginx -o json # JSON grype nginx -o cyclonedx # CycloneDX grype nginx -o sarif # SARIF grype nginx -o template -t custom.tmpl # Custom template
FILTERING#
# By severity
grype nginx --only-fixed # Only fixable
grype nginx --fail-on critical # Fail on critical
grype nginx --fail-on high # Fail on high+
# Ignore CVEs (.grype.yaml)
ignore:
- vulnerability: CVE-2023-12345
- vulnerability: CVE-2023-67890
package:
name: openssl
type: deb
# Update vulnerability database
grype db update
grype db status # Check DB age
SYFT (SBOM GENERATOR)#
# Generate SBOM first, then scan syft nginx:latest -o json > sbom.json grype sbom:sbom.json
TIPS#
- Pair with Syft for SBOM generation + vulnerability scanning - --fail-on critical for CI/CD quality gates - Faster than Trivy for image-only scanning - Use .grype.yaml for persistent ignore rules - SARIF output for GitHub/GitLab security tabs - Combine with Trivy for cross-validation - Regular db update ensures latest CVE coverage - Supports distroless and scratch-based images
GRYPE CHEATSHEET
=================
Source: https://cheatsheet.johlem.net
Container and filesystem vulnerability scanner by Anchore.
Scans container images, SBOMs, and directories for known CVEs.
INSTALLATION
-------------
curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh
# Or: brew install grype
SCANNING
---------
# Container image
grype nginx:latest
grype python:3.11
grype myapp:v1.0
# From Docker daemon
grype docker:mylocal-image
# Filesystem
grype dir:/path/to/project
# SBOM (from Syft)
grype sbom:sbom.json
# Tar archive
grype path/to/image.tar
# OCI directory
grype oci-dir:/path/to/oci
OUTPUT
-------
grype nginx -o table # Default table
grype nginx -o json # JSON
grype nginx -o cyclonedx # CycloneDX
grype nginx -o sarif # SARIF
grype nginx -o template -t custom.tmpl # Custom template
FILTERING
----------
# By severity
grype nginx --only-fixed # Only fixable
grype nginx --fail-on critical # Fail on critical
grype nginx --fail-on high # Fail on high+
# Ignore CVEs (.grype.yaml)
ignore:
- vulnerability: CVE-2023-12345
- vulnerability: CVE-2023-67890
package:
name: openssl
type: deb
# Update vulnerability database
grype db update
grype db status # Check DB age
SYFT (SBOM GENERATOR)
-----------------------
# Generate SBOM first, then scan
syft nginx:latest -o json > sbom.json
grype sbom:sbom.json
TIPS
-----
- Pair with Syft for SBOM generation + vulnerability scanning
- --fail-on critical for CI/CD quality gates
- Faster than Trivy for image-only scanning
- Use .grype.yaml for persistent ignore rules
- SARIF output for GitHub/GitLab security tabs
- Combine with Trivy for cross-validation
- Regular db update ensures latest CVE coverage
- Supports distroless and scratch-based images
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.