Grype is an open-source vulnerability scanner from Anchore that finds known CVEs in container images, directories and SBOMs. Use it to scan images in CI/CD, fail builds on severity, triage and suppress false positives, upload SARIF to GitHub code scanning, or scan Syft-generated SBOMs.