# Grype

**URL:** https://anchorecommunity.discourse.group/c/grype/6.md

[Latest](https://anchorecommunity.discourse.group/latest.md) · [Categories](https://anchorecommunity.discourse.group/categories.md) · [Tags](https://anchorecommunity.discourse.group/tags.md)

---

## [About the Grype category](https://anchorecommunity.discourse.group/t/about-the-grype-category/11)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [May 28, 2024, 9:59am UTC](https://anchorecommunity.discourse.group/t/about-the-grype-category/11 "2024-05-28T09:59:18Z")

</div>

Grype This category is used for discussion of Grype - the vulnerability scanner for container images and filesystems Discussion of the development and use of Grype is on topic here. We also welcome support requ…

---

## [Tracing elements of grype json output](https://anchorecommunity.discourse.group/t/tracing-elements-of-grype-json-output/659)

<div class="topic-metadata">

**Author:** [@anwarani-ext-ks](https://anchorecommunity.discourse.group/u/anwarani-ext-ks)\
**Replies:** 0\
**Last updated:** [August 20, 2026, 3:52am UTC](https://anchorecommunity.discourse.group/t/tracing-elements-of-grype-json-output/659 "2026-08-20T03:52:12Z")

</div>

Howdy, I have a couple of questions regarding grype vuln scan output: How can I trace which provider the matches.vulnerability.description field comes from? Can I set nvd as the first option for the matches.vulnerabil…

---

## [Adding a new matcher](https://anchorecommunity.discourse.group/t/adding-a-new-matcher/656)

<div class="topic-metadata">

**Author:** [@thaines](https://anchorecommunity.discourse.group/u/thaines)\
**Replies:** 0\
**Last updated:** [July 21, 2026, 8:14pm UTC](https://anchorecommunity.discourse.group/t/adding-a-new-matcher/656 "2026-07-21T20:14:35Z")

</div>

spack is a package manager similar to conan or vcpkg that can build software from source covering a wide array of languages, runtimes, compilers, and configurations (it can also use signed packages from its public binary…

---

## [Grype-DB has no new Ubuntu data since 19 June](https://anchorecommunity.discourse.group/t/grype-db-has-no-new-ubuntu-data-since-19-june/653)

<div class="topic-metadata">

**Author:** [@floric](https://anchorecommunity.discourse.group/u/floric)\
**Replies:** 1\
**Last updated:** [June 24, 2026, 11:21am UTC](https://anchorecommunity.discourse.group/t/grype-db-has-no-new-ubuntu-data-since-19-june/653 "2026-06-24T11:21:36Z")

</div>

Hey :slight\_smile: unfortunately the Grype-DB ist outdated since 06/19. Can you check it? Kind regards

---

## [Indirect matches (vulnerabilities affecting the upstream packages) are sometimes too broad](https://anchorecommunity.discourse.group/t/indirect-matches-vulnerabilities-affecting-the-upstream-packages-are-sometimes-too-broad/523)

<div class="topic-metadata">

**Author:** [@staticnoise](https://anchorecommunity.discourse.group/u/staticnoise)\
**Replies:** 11\
**Last updated:** [June 18, 2026, 1:41pm UTC](https://anchorecommunity.discourse.group/t/indirect-matches-vulnerabilities-affecting-the-upstream-packages-are-sometimes-too-broad/523 "2026-06-18T13:41:28Z")

</div>

Hello, I want to ask about upstream matches in Grype. Currently Grype results seem to include all vulnerabilities affecting the upstream package. For example, python-perf package with upstream of kernel includes all v…

---

## [EOL can be developed in grype](https://anchorecommunity.discourse.group/t/eol-can-be-developed-in-grype/420)

<div class="topic-metadata">

**Author:** [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Replies:** 2\
**Last updated:** [May 1, 2026, 6:42pm UTC](https://anchorecommunity.discourse.group/t/eol-can-be-developed-in-grype/420 "2026-05-01T18:42:08Z")

</div>

Today I saw the API of EOL was upgraded and full information can be extracted from the API. I think it is possible now to add this information to grype. here is the relevant issue - Add capability to detect EOL package…

---

## [Support for PostgreSQL or MariaDB as a backend for the Grype database](https://anchorecommunity.discourse.group/t/support-for-postgresql-or-mariadb-as-a-backend-for-the-grype-database/616)

<div class="topic-metadata">

**Author:** [@enzofrnt](https://anchorecommunity.discourse.group/u/enzofrnt)\
**Replies:** 3\
**Last updated:** [May 1, 2026, 5:21pm UTC](https://anchorecommunity.discourse.group/t/support-for-postgresql-or-mariadb-as-a-backend-for-the-grype-database/616 "2026-05-01T17:21:13Z")

</div>

Hello, First of all, thank you for the work you are doing around open-source tools for vulnerability and SBOM management. The Grype database you use is very powerful, but its usage is currently limited to a SQLite data…

---

## [Evaluating Anchore Score Alignment with ISO/SAE 21434 and Automotive Functional Safety Risk](https://anchorecommunity.discourse.group/t/evaluating-anchore-score-alignment-with-iso-sae-21434-and-automotive-functional-safety-risk/598)

<div class="topic-metadata">

**Author:** [@Devashri\_Datta](https://anchorecommunity.discourse.group/u/Devashri_Datta)\
**Replies:** 3\
**Last updated:** [February 6, 2026, 7:00pm UTC](https://anchorecommunity.discourse.group/t/evaluating-anchore-score-alignment-with-iso-sae-21434-and-automotive-functional-safety-risk/598 "2026-02-06T19:00:00Z")

</div>

Dear Anchore Engineering & Community Team, I am evaluating how the Anchore Score—your composite security index comprising CVSS, EPSS, and CISA KEV status—is interpreted within highly regulated software supply chains, sp…

---

## [CVE fallback for other ecosystems](https://anchorecommunity.discourse.group/t/cve-fallback-for-other-ecosystems/597)

<div class="topic-metadata">

**Author:** [@bhogan](https://anchorecommunity.discourse.group/u/bhogan)\
**Replies:** 5\
**Last updated:** [February 4, 2026, 4:03am UTC](https://anchorecommunity.discourse.group/t/cve-fallback-for-other-ecosystems/597 "2026-02-04T04:03:36Z")

</div>

I am curious about CPE fallback matching. The docs linked here list 5 specific package types that rely on CPE matching (binary executables, Homebrew, Jenkins, Conda, WordPress). Is that list exhaustive, or should we ex…

---

## [Grype is reporting a high number of vulnerabilities in one instance, while the other scan returns zero findings.](https://anchorecommunity.discourse.group/t/grype-is-reporting-a-high-number-of-vulnerabilities-in-one-instance-while-the-other-scan-returns-zero-findings/594)

<div class="topic-metadata">

**Author:** [@Phong\_Tr\_n](https://anchorecommunity.discourse.group/u/Phong_Tr_n)\
**Replies:** 2\
**Last updated:** [January 26, 2026, 2:13am UTC](https://anchorecommunity.discourse.group/t/grype-is-reporting-a-high-number-of-vulnerabilities-in-one-instance-while-the-other-scan-returns-zero-findings/594 "2026-01-26T02:13:51Z")

</div>

Dear Anchore, I apologize for the interruption, but I am encountering a technical issue and would greatly appreciate your expert opinion. Our initial image scans were completely clean and remain so to this day. However…

---

## [Help with new provider](https://anchorecommunity.discourse.group/t/help-with-new-provider/596)

<div class="topic-metadata">

**Author:** [@Ildar\_Mulyukov](https://anchorecommunity.discourse.group/u/Ildar_Mulyukov)\
**Replies:** 1\
**Last updated:** [January 23, 2026, 11:35am UTC](https://anchorecommunity.discourse.group/t/help-with-new-provider/596 "2026-01-23T11:35:49Z")

</div>

I’ve made some patches for Vunnel and Grype: Draft: providers: add BellSoft OSV provider by i-bs · Pull Request #924 · anchore/vunnel · GitHub . It builds fine but Grype can’t find the relevant CVE data. Can anyone plea…

---

## [No Vulnerability DB Updates](https://anchorecommunity.discourse.group/t/no-vulnerability-db-updates/497)

<div class="topic-metadata">

**Author:** [@henrysachs](https://anchorecommunity.discourse.group/u/henrysachs)\
**Replies:** 10\
**Last updated:** [December 4, 2025, 9:40am UTC](https://anchorecommunity.discourse.group/t/no-vulnerability-db-updates/497 "2025-12-04T09:40:56Z")

</div>

Hey there, it seems grype doesn’t have a new DB listed on: https://grype.anchore.io/databases/v6/latest.json is everything alright with the pipeline as normally you built a new db every day

---

## [Listing the image that is being scanned](https://anchorecommunity.discourse.group/t/listing-the-image-that-is-being-scanned/587)

<div class="topic-metadata">

**Author:** [@vbakke](https://anchorecommunity.discourse.group/u/vbakke)\
**Replies:** 4\
**Last updated:** [November 28, 2025, 8:31am UTC](https://anchorecommunity.discourse.group/t/listing-the-image-that-is-being-scanned/587 "2025-11-28T08:31:12Z")

</div>

Hi I testing rivy and grype. Running grype . --by-cve in my Java home folder both reported a dependency problem. I fixed the pom.xml file, re-compiled, and re-executed both trivy and grype. Only trivy reported the pro…

---

## [Does grype fully handle the Trivy based SBOM vulnerability analysis?](https://anchorecommunity.discourse.group/t/does-grype-fully-handle-the-trivy-based-sbom-vulnerability-analysis/584)

<div class="topic-metadata">

**Author:** [@Kowshik\_Chy](https://anchorecommunity.discourse.group/u/Kowshik_Chy)\
**Replies:** 2\
**Last updated:** [November 3, 2025, 9:15pm UTC](https://anchorecommunity.discourse.group/t/does-grype-fully-handle-the-trivy-based-sbom-vulnerability-analysis/584 "2025-11-03T21:15:46Z")

</div>

I run trivy for SBOM generation and analyze it with grype, so I found that grype did not find vulnerabilities in the trivy-based SBOM

---

## [Does grype covers urls instead of version in npm?](https://anchorecommunity.discourse.group/t/does-grype-covers-urls-instead-of-version-in-npm/583)

<div class="topic-metadata">

**Author:** [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Replies:** 1\
**Last updated:** [November 3, 2025, 9:13pm UTC](https://anchorecommunity.discourse.group/t/does-grype-covers-urls-instead-of-version-in-npm/583 "2025-11-03T21:13:35Z")

</div>

I recently read an article here about ‘hidden’ dependencies. i wonder if grype alerts on this kind of vulnerabilities?

---

## [Weak SSL config for https://grype.anchore.io](https://anchorecommunity.discourse.group/t/weak-ssl-config-for-https-grype-anchore-io/576)

<div class="topic-metadata">

**Author:** [@TimBim](https://anchorecommunity.discourse.group/u/TimBim)\
**Replies:** 3\
**Last updated:** [October 14, 2025, 6:24am UTC](https://anchorecommunity.discourse.group/t/weak-ssl-config-for-https-grype-anchore-io/576 "2025-10-14T06:24:12Z")

</div>

Dear Grype team, We need to automatically download/mirror the grype database to an air-gapped environment from URL grype.anchore.io/databases/v6/latest.json as you have discontinued the hosting from toolbox-data.anchore…

---

## [Not supported pnpm yet?](https://anchorecommunity.discourse.group/t/not-supported-pnpm-yet/575)

<div class="topic-metadata">

**Author:** [@takuyahara](https://anchorecommunity.discourse.group/u/takuyahara)\
**Replies:** 4\
**Last updated:** [October 10, 2025, 1:43am UTC](https://anchorecommunity.discourse.group/t/not-supported-pnpm-yet/575 "2025-10-10T01:43:23Z")

</div>

I just started to try grype and have a question; doesn’t it support pnpm monorepo? Downloading pnpm’s SBOM from GitHub and running cat pnpm\_pnpm\_66e1aa.json | grype resulted like the following excerpt. NAME …

---

## [Adding support for container first distro: 0-deb](https://anchorecommunity.discourse.group/t/adding-support-for-container-first-distro-0-deb/555)

<div class="topic-metadata">

**Author:** [@abhishek](https://anchorecommunity.discourse.group/u/abhishek)\
**Replies:** 2\
**Last updated:** [September 10, 2025, 11:59am UTC](https://anchorecommunity.discourse.group/t/adding-support-for-container-first-distro-0-deb/555 "2025-09-10T11:59:10Z")

</div>

Hi Anchore team, We at KoalaLab(https://www.koalalab.com) have built a container first distro: 0-deb. The idea is to package upstream sources as per debian standards but with minimalism and container in mind. We use thi…

---

## [Grype .98 misidentifies package versions](https://anchorecommunity.discourse.group/t/grype-98-misidentifies-package-versions/541)

<div class="topic-metadata">

**Author:** [@wagner-robert](https://anchorecommunity.discourse.group/u/wagner-robert)\
**Replies:** 10\
**Last updated:** [August 27, 2025, 2:11pm UTC](https://anchorecommunity.discourse.group/t/grype-98-misidentifies-package-versions/541 "2025-08-27T14:11:08Z")

</div>

All, I logged this bug. Grype .98 misidentifies the container package version · Issue #2884 · anchore/grype I am trying to see if there is a way to debug this and better understand exactly why Grype is saying I have ve…

---

## [Adding Ignore Filters for Vex Entries](https://anchorecommunity.discourse.group/t/adding-ignore-filters-for-vex-entries/537)

<div class="topic-metadata">

**Author:** [@CrosleyZack](https://anchorecommunity.discourse.group/u/CrosleyZack)\
**Replies:** 3\
**Last updated:** [August 21, 2025, 8:57pm UTC](https://anchorecommunity.discourse.group/t/adding-ignore-filters-for-vex-entries/537 "2025-08-21T20:57:29Z")

</div>

I am working on adding an OpenVEX feed from Chainguard to help filter out false positive vulnerability results in Chainguard Libraries. So far, I have PRs adding OpenVEX parsing to vunnel and store as data.Entry’s in gry…

---

## [CVE reported until CVSS Score was set](https://anchorecommunity.discourse.group/t/cve-reported-until-cvss-score-was-set/502)

<div class="topic-metadata">

**Author:** [@Nicolas\_F](https://anchorecommunity.discourse.group/u/Nicolas_F)\
**Replies:** 1\
**Last updated:** [July 21, 2025, 11:33am UTC](https://anchorecommunity.discourse.group/t/cve-reported-until-cvss-score-was-set/502 "2025-07-21T11:33:08Z")

</div>

Hi team, Currently I’m implementing grype to perform the proper security scanning for my containers. One specific CVE ( CVE-2024-42516) for apache httpd was recently published on Jul 10th and got updated by Jul 15 (th…

---

## [How to tell where vulnerability is in large repo?](https://anchorecommunity.discourse.group/t/how-to-tell-where-vulnerability-is-in-large-repo/472)

<div class="topic-metadata">

**Author:** [@RPGillespie6](https://anchorecommunity.discourse.group/u/RPGillespie6)\
**Replies:** 3\
**Last updated:** [July 11, 2025, 5:06pm UTC](https://anchorecommunity.discourse.group/t/how-to-tell-where-vulnerability-is-in-large-repo/472 "2025-07-11T17:06:24Z")

</div>

Is it possible to surface where grype is uncovering a vulnerability when doing filesystem scans? For example, if I go to a repo and do grype . I might get an output like: NAME INSTALLED …

---

## [Another look at Grype - New Features](https://anchorecommunity.discourse.group/t/another-look-at-grype-new-features/481)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 1\
**Last updated:** [June 26, 2025, 12:41pm UTC](https://anchorecommunity.discourse.group/t/another-look-at-grype-new-features/481 "2025-06-26T12:41:32Z")

</div>

We just published a new blog: Time to Take Another Look at Grype: A Year of Major Improvements | Anchore There’s a lot of commands in there - many in screenshots, so I thought I’d pull them all together here, for easy c…

---

## [Clarification about ELSA reports returned by Grype](https://anchorecommunity.discourse.group/t/clarification-about-elsa-reports-returned-by-grype/439)

<div class="topic-metadata">

**Author:** [@enzofrnt](https://anchorecommunity.discourse.group/u/enzofrnt)\
**Replies:** 6\
**Last updated:** [June 17, 2025, 2:34pm UTC](https://anchorecommunity.discourse.group/t/clarification-about-elsa-reports-returned-by-grype/439 "2025-06-17T14:34:35Z")

</div>

Hi, Grype is returning ELSA entries, but as I understand it, ELSA reports are not actual vulnerabilities themselves. Instead, they are advisories that may reference multiple vulnerabilities (CVEs) and may apply to multi…

---

## [V5 schema eol in grype](https://anchorecommunity.discourse.group/t/v5-schema-eol-in-grype/346)

<div class="topic-metadata">

**Author:** [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Replies:** 5\
**Last updated:** [June 9, 2025, 2:05pm UTC](https://anchorecommunity.discourse.group/t/v5-schema-eol-in-grype/346 "2025-06-09T14:05:42Z")

</div>

hi, when v5 will be eol (meaning un-supported like v1, v2) will the schema of grype change? (breaking changes) thanks!

---

## [SUSE Linux matching impacted by SUSE outage](https://anchorecommunity.discourse.group/t/suse-linux-matching-impacted-by-suse-outage/440)

<div class="topic-metadata">

**Author:** [@willmurphy](https://anchorecommunity.discourse.group/u/willmurphy)\
**Replies:** 1\
**Last updated:** [May 22, 2025, 3:10pm UTC](https://anchorecommunity.discourse.group/t/suse-linux-matching-impacted-by-suse-outage/440 "2025-05-22T15:10:39Z")

</div>

Hello Grype users, Since Friday, May 16, 2025 the site where SUSE Linux publish their vulnerability data has been consistently timing out, and now redirects to an error page. Here’s a link to test if that’s still true:…

---

## [Unable to use html template when using grype in a container in a jenkins job to scan docker images](https://anchorecommunity.discourse.group/t/unable-to-use-html-template-when-using-grype-in-a-container-in-a-jenkins-job-to-scan-docker-images/429)

<div class="topic-metadata">

**Author:** [@sboyadjiev](https://anchorecommunity.discourse.group/u/sboyadjiev)\
**Replies:** 7\
**Last updated:** [May 22, 2025, 10:10am UTC](https://anchorecommunity.discourse.group/t/unable-to-use-html-template-when-using-grype-in-a-container-in-a-jenkins-job-to-scan-docker-images/429 "2025-05-22T10:10:17Z")

</div>

Hi, I have tried implementing Grype in a jenkins job to use for security purposes. I got it to use syft’s sbom (which is also in a container) and give a report but the output looks like the image below. Is this an issue…

---

## [List of affected ranges vs list of fixes?](https://anchorecommunity.discourse.group/t/list-of-affected-ranges-vs-list-of-fixes/418)

<div class="topic-metadata">

**Author:** [@willmurphy](https://anchorecommunity.discourse.group/u/willmurphy)\
**Replies:** 1\
**Last updated:** [April 30, 2025, 11:06am UTC](https://anchorecommunity.discourse.group/t/list-of-affected-ranges-vs-list-of-fixes/418 "2025-04-30T11:06:17Z")

</div>

Hi friends! I’m working on a Grype feature where users will be able to tell grype that they have Ubuntu Pro / ESM available, and Grype will suggest fixes that involve pro-only releases. Right now, some users are frustrat…

---

## [Grype is wrong about CVE-2024-37371 in libkrb5-3@1.20.1-2+deb12u2](https://anchorecommunity.discourse.group/t/grype-is-wrong-about-cve-2024-37371-in-libkrb5-3-1-20-1-2-deb12u2/387)

<div class="topic-metadata">

**Author:** [@Omri1100](https://anchorecommunity.discourse.group/u/Omri1100)\
**Replies:** 6\
**Last updated:** [April 9, 2025, 8:46am UTC](https://anchorecommunity.discourse.group/t/grype-is-wrong-about-cve-2024-37371-in-libkrb5-3-1-20-1-2-deb12u2/387 "2025-04-09T08:46:15Z")

</div>

Im using grype in order to see what CVEs are a match for libkrb5-3@1.20.1-2+deb12u2 (purl: ''pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u2?arch=amd64&upstream=krb5&distro=debian") And im getting CVE-2024-37371 as a match. …

---

## [Cvss4 vs cvss3 and issues downloading grype db](https://anchorecommunity.discourse.group/t/cvss4-vs-cvss3-and-issues-downloading-grype-db/398)

<div class="topic-metadata">

**Author:** [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Replies:** 0\
**Last updated:** [April 7, 2025, 12:25pm UTC](https://anchorecommunity.discourse.group/t/cvss4-vs-cvss3-and-issues-downloading-grype-db/398 "2025-04-07T12:25:44Z")

</div>

hi! how can i know if a CVE has only cvss 4 (and not cvss 3) is it possible? moreover, i recently have issues downloading the db manually. when i run grype db list and after that try to download the url i receive 404 …

[Next page](https://anchorecommunity.discourse.group/c/grype/6.md?page=1)
