What is Grype?

An open-source security tool that detects vulnerabilities in containerized applications and filesystem artifacts across multiple operating systems and programming language ecosystems.

Independently observed

Grype pricing

We don't have Grype's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Self-hosted

Security & compliance

Known vulnerabilities: 1 (1 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality

Grype alternatives

Other container security we track, ranked by the same independent score.

All Grype alternatives, ranked →

Compare Grype

Side by side against other container security, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Grype, not the verdict.

Balanced composite 55 / 100
low · 24%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Price level1000.055.2
Release cadence930.054.9
Development activity420.094.0
Security score820.043.4
Pricing transparency250.082.1
Stars780.032.0
Dependent projects200.061.2
Reliability00.070.0-
Capabilities00.080.0-
Integrations00.090.0-
Security posture00.070.0-
Package downloads00.140.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d21mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars12,787highsource · 2026-08-26 · 90%
Dependent repos14highsource · 2026-08-26 · 85%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-08-26 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-26 · 95%

Pricing

AttributeValueEvidence
Modelcommerciallowsource · 2026-08-26 · 48%
Free tierYesmediumsource · 2026-08-18 · 60%
Price levelfreemediumsource · 2026-08-18 · 60%

Release

AttributeValueEvidence
Cadence days12mediumsource · 2026-08-26 · 70%
History20 itemsmediumsource · 2026-08-26 · 70%

Security

AttributeValueEvidence
Scorecard8.2highsource · 2026-08-26 · 90%
VulnerabilitiesCount: 1 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fanchore%2Fgrype&per_page=100 · Last 12m: 1 · Max severity: HIGHhighsource · 2026-08-26 · 90%