
一个用于容器镜像和文件系统的漏洞扫描器
一款用于容器镜像和文件系统的漏洞扫描器。

[!TIP] 初次使用 Grype?请查看入门指南获取完整教程!
最快速的安装方式:
curl -sSfL https://get.anchore.io/grype | sudo sh -s -- -b /usr/local/bin
[!TIP] 更多获取 Grype 的方式(包括 Homebrew、Docker、Chocolatey、MacPorts 等)请参阅安装文档!
扫描容器镜像或目录中的漏洞:
# container image
grype alpine:latest
# directory
grype ./my-project
在 Linux 上,grype 可以在明确指定时扫描本地 containers-storage 存储中的镜像(例如使用 Buildah 或 Podman 构建的镜像);普通的镜像引用不会查找该存储:
grype --from containers-storage localhost/myimage:latest
# rootless stores must be read from inside the builder's user namespace
podman unshare grype --from containers-storage localhost/myimage:latest
此功能已包含在 Linux 发行版二进制文件中。从源码构建时,请添加 -tags containers_image_openpgp,exclude_graphdriver_btrfs。
扫描 SBOM 以实现更快速的漏洞检测:
# scan a Syft SBOM
grype sbom:./sbom.json
# pipe an SBOM into Grype
cat ./sbom.json | grype
[!TIP] 查看入门指南以探索所有功能和特性。
我们鼓励用户通过提交 issue来帮助改进这些工具,无论是发现 bug 还是希望添加新功能。 如果您有兴趣贡献代码,请查看我们的贡献概述和开发者专属文档。
Grype 的开发由 Anchore 赞助,并基于 Apache-2.0 许可证发布。
Grype 标志由 Anchore 创作,基于 CC BY 4.0 许可协议授权。
如需 Syft 或 Grype 的商业支持选项,请联系 Anchore。
Grype 团队定期举行线上社区会议。欢迎所有人参加并带来讨论话题。