# Tracing elements of grype json output

**URL:** <https://anchorecommunity.discourse.group/t/tracing-elements-of-grype-json-output/659>\
**Category:** Grype\
**Created:** [August 20, 2026, 3:52am UTC](https://anchorecommunity.discourse.group/t/tracing-elements-of-grype-json-output/659 "2026-08-20T03:52:12Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![anwarani-ext-ks](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/anwarani-ext-ks/32/472_2.png) [@anwarani-ext-ks](https://anchorecommunity.discourse.group/u/anwarani-ext-ks)\
**Post date:** [August 20, 2026, 3:52am UTC](https://anchorecommunity.discourse.group/t/tracing-elements-of-grype-json-output/659/1 "2026-08-20T03:52:12Z")

</div>

Howdy,

I have a couple of questions regarding grype vuln scan output:

- How can I trace which provider the `matches.vulnerability.description` field comes from?
- Can I set `nvd` as the first option for the `matches.vulnerability.description` field?

Also, what provider precedence does `grype-db`/`vunnel` when creating the nightly db?

Thank you,

Drew
