# Grype

> Apache-2.0 SBOM-first vulnerability scanner from Anchore; free CLI

**Category:** DevOps  
**Pricing:** open-source  
**URL:** https://anchore.com/grype/  
**GitHub:** https://github.com/anchore/grype  
**Added:** 2026-09-04

---

## The Hook

Grype is vuln matching against SBOMs when Trivy is the all-in-one and you already emit Syft/SPDX/CycloneDX.

## What's Good

Apache-2.0. Scan images, dirs, or SBOMs; pairs with Syft (generate once, rescan often). Offline DB after download. Transparent matching logic. No feature gate on the CLI.

## The Catch

Vuln scanner — not Trivy's IaC/secrets swiss-army, not Cosign signing, not Anchore Enterprise governance UI. You still triage CVEs. Anchore monetizes Enterprise separately.

## Verdict

Apache-2.0 SBOM vuln scanner. Free CLI; Enterprise is the paid cousin.
