{"data":{"slug":"grype","name":"Grype","tagline":"Apache-2.0 SBOM-first vulnerability scanner from Anchore; free CLI","category":"devops","categoryName":"DevOps","url":"https://anchore.com/grype/","github":"https://github.com/anchore/grype","pricing":"open-source","hook":"Grype is vuln matching against SBOMs when Trivy is the all-in-one and you already emit Syft/SPDX/CycloneDX.","whatsGood":"Apache-2.0. Scan images, dirs, or SBOMs; pairs with Syft (generate once, rescan often). Offline DB after download. Transparent matching logic. No feature gate on the CLI.","theCatch":"Vuln scanner — not Trivy's IaC/secrets swiss-army, not Cosign signing, not Anchore Enterprise governance UI. You still triage CVEs. Anchore monetizes Enterprise separately.","verdict":"Apache-2.0 SBOM vuln scanner. Free CLI; Enterprise is the paid cousin.","addedAt":"2026-09-04","featured":false,"domain":"DevOps","subSpecialty":"Security","capabilities":["vuln","sbom","ci"],"surfaces":["CLI","Self-host"],"ecosystem":["Multi-platform","Go"],"licenseModel":"Apache-2.0","githubStars":12838},"related":[{"slug":"github-actions","name":"GitHub Actions","tagline":"CI/CD that lives where your code does"},{"slug":"docker","name":"Docker","tagline":"Container runtime that changed deployment"},{"slug":"kubernetes","name":"Kubernetes","tagline":"Container orchestration at scale"},{"slug":"terraform","name":"Terraform","tagline":"Infrastructure as code that actually works"},{"slug":"pulumi","name":"Pulumi","tagline":"Infrastructure as code in real languages"}],"links":{"self":"/api/gems/grype","html":"/gems/grype","markdown":"/gems/grype.md","category":"/api/gems?category=devops","categoryPage":"/stacks/devops"}}