mirror of
https://github.com/webinstall/webi-installers.git
synced 2026-05-17 06:06:35 +00:00
936 B
936 B
title, homepage, tagline
| title | homepage | tagline |
|---|---|---|
| Grype | https://github.com/anchore/grype/ | Grype is a vulnerability scanner for container images and filesystems. |
To update or switch versions, run webi grype@stable (or @v0.6, @beta,
etc)
Cheat Sheet
It also helps find vulnerabilites for major operating system and language-specific packages. Supports Docker, OCI and Singularity image formats, OpenVEX support for filtering and augmenting scanning results. Works with
syft, a powerfulSBOM(software bill of materials) tool for container images and filesystems
To scan for vulnerabilities in an image:
grype <image>
To scan all image layers
grype <image> --scope all-layers
To run grype from a Docker container so it can scan a running container
docker run --rm \
--volume /var/run/docker.sock:/var/run/docker.sock \
--name Grype anchore/grype:latest \
$(ImageName):$(ImageTag)