# Grype - v0.95.0 released

**URL:** <https://anchorecommunity.discourse.group/t/grype-v0-95-0-released/488>\
**Category:** Announcements\
**Tags:** release\
**Created:** [July 2, 2025, 5:29pm UTC](https://anchorecommunity.discourse.group/t/grype-v0-95-0-released/488 "2025-07-02T17:29:37Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [July 2, 2025, 5:29pm UTC](https://anchorecommunity.discourse.group/t/grype-v0-95-0-released/488/1 "2025-07-02T17:29:37Z")

</div>

> **[Release v0.95.0 · anchore/grype](https://github.com/anchore/grype/releases/tag/v0.95.0)**
>
> Added Features
> 
> Add string severity to db search json results \[#2730 @wagoodman\]
> Add package specifier overrides for kb, dpkg, and apkg \[#2742 @westonsteimel\]
> 
> Bug Fixes
> 
> show related NVD records f...

✨ **Help shape the future of Grype! Share your thoughts in our [quick 5-question survey](https://forms.gle/JPWkTaHwffyYXzTx9)**. Your feedback will guide our development priorities and help us better serve your needs. Thank you! 🙌

## Release Notes:

## Version v0.95.0

### Added Features

- Add string severity to db search json results [#2730](https://github.com/anchore/grype/pull/2730) [@wagoodman](https://github.com/wagoodman)
- Add package specifier overrides for `kb`, `dpkg`, and `apkg` [#2742](https://github.com/anchore/grype/pull/2742) [@westonsteimel](https://github.com/westonsteimel)

### Bug Fixes

- show related NVD records for non-NVD matches [#2755](https://github.com/anchore/grype/pull/2755) [@kzantow](https://github.com/kzantow)
- assume that a vulnerability with no ranges is always vulnerable [#2759](https://github.com/anchore/grype/pull/2759) [@wagoodman](https://github.com/wagoodman)
- DB should hydrate for when the client has new features [#2758](https://github.com/anchore/grype/pull/2758) [@wagoodman](https://github.com/wagoodman)
- show relationship back to NVD for all CVE ids [#2756](https://github.com/anchore/grype/pull/2756) [@westonsteimel](https://github.com/westonsteimel)
- properly escape CPE segments [#2731](https://github.com/anchore/grype/pull/2731) [@kzantow](https://github.com/kzantow)
- msrc matcher should search by package ecosystem, not by distro [#2748](https://github.com/anchore/grype/pull/2748) [@westonsteimel](https://github.com/westonsteimel)
- Grype does not report any vulnerabilities for CPEs with target\_sw field set to value that does not correspond to known package type [#2768](https://github.com/anchore/grype/issues/2768) [#2772](https://github.com/anchore/grype/pull/2772) [@willmurphyscode](https://github.com/willmurphyscode)
- malformed CPE in grype db search output [#2767](https://github.com/anchore/grype/issues/2767) [#2769](https://github.com/anchore/grype/pull/2769) [@westonsteimel](https://github.com/westonsteimel)
- vex documents from the --vex flag do get processed or applied to the output correctly [#1836](https://github.com/anchore/grype/issues/1836) [#2741](https://github.com/anchore/grype/pull/2741) [@willmurphyscode](https://github.com/willmurphyscode)

### Additional Changes

- replace deprecated GoReleaser configurations [#2729](https://github.com/anchore/grype/pull/2729) [@emmanuel-ferdman](https://github.com/emmanuel-ferdman)
- specify types for all match details [#2762](https://github.com/anchore/grype/pull/2762) [@wagoodman](https://github.com/wagoodman)
- Refactor the version package [#2735](https://github.com/anchore/grype/pull/2735) [@wagoodman](https://github.com/wagoodman)

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.94.0...v0.95.0)**
