← All cheat sheets

GRYPE

Plain-text reference · 2 KB. Read it, search it (Ctrl-F) or print it.

Container and filesystem vulnerability scanner by Anchore.
Scans container images, SBOMs, and directories for known CVEs.

INSTALLATION#

curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh
# Or: brew install grype

SCANNING#

# Container image
grype nginx:latest
grype python:3.11
grype myapp:v1.0

# From Docker daemon
grype docker:mylocal-image

# Filesystem
grype dir:/path/to/project

# SBOM (from Syft)
grype sbom:sbom.json

# Tar archive
grype path/to/image.tar

# OCI directory
grype oci-dir:/path/to/oci

OUTPUT#

grype nginx -o table                        # Default table
grype nginx -o json                         # JSON
grype nginx -o cyclonedx                    # CycloneDX
grype nginx -o sarif                        # SARIF
grype nginx -o template -t custom.tmpl      # Custom template

FILTERING#

# By severity
grype nginx --only-fixed                    # Only fixable
grype nginx --fail-on critical              # Fail on critical
grype nginx --fail-on high                  # Fail on high+

# Ignore CVEs (.grype.yaml)
ignore:
  - vulnerability: CVE-2023-12345
  - vulnerability: CVE-2023-67890
    package:
      name: openssl
      type: deb

# Update vulnerability database
grype db update
grype db status                             # Check DB age

SYFT (SBOM GENERATOR)#

# Generate SBOM first, then scan
syft nginx:latest -o json > sbom.json
grype sbom:sbom.json

TIPS#

  - Pair with Syft for SBOM generation + vulnerability scanning
  - --fail-on critical for CI/CD quality gates
  - Faster than Trivy for image-only scanning
  - Use .grype.yaml for persistent ignore rules
  - SARIF output for GitHub/GitLab security tabs
  - Combine with Trivy for cross-validation
  - Regular db update ensures latest CVE coverage
  - Supports distroless and scratch-based images

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.