Files
vim-ale/grype/README.md
2023-10-12 05:15:27 +00:00

936 B

title, homepage, tagline
title homepage tagline
Grype https://github.com/anchore/grype/ Grype is a vulnerability scanner for container images and filesystems.

To update or switch versions, run webi grype@stable (or @v0.6, @beta, etc)

Cheat Sheet

It also helps find vulnerabilites for major operating system and language-specific packages. Supports Docker, OCI and Singularity image formats, OpenVEX support for filtering and augmenting scanning results. Works with syft, a powerful SBOM (software bill of materials) tool for container images and filesystems

To scan for vulnerabilities in an image:

grype <image>

To scan all image layers

grype <image> --scope all-layers

To run grype from a Docker container so it can scan a running container

docker run --rm \
--volume /var/run/docker.sock:/var/run/docker.sock \
--name Grype anchore/grype:latest \
$(ImageName):$(ImageTag)