What it does. Scans container images, filesystems, and SBOMs for known CVEs with Anchore Grype, matching Syft-generated SBOM packages against NVD, GitHub Advisories, and OS-specific feeds with configurable severity thresholds and failure gates. Use when Grype or Syft is the chosen toolchain, when scanning an existing SBOM rather than an image, or when gating a build on severity. Keywords: Grype, Syft, SBOM, NVD, GitHub Advisory, --fail-on, severity threshold. Do not use when the toolchain is Trivy - use scanning-docker-images-with-trivy. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-container-images-with-grype, or copy the skill folder into ~/.claude/skills/scanning-container-images-with-grype/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/scanning-container-images-with-grype/SKILL.md
SKILL.md (verbatim)
name: scanning-container-images-with-grype
description: >-
Scans container images, filesystems, and SBOMs for known CVEs with Anchore Grype, matching
Syft-generated SBOM packages against NVD, GitHub Advisories, and OS-specific feeds with
configurable severity thresholds and failure gates. Use when Grype or Syft is the chosen
toolchain, when scanning an existing SBOM rather than an image, or when gating a build on
severity. Keywords: Grype, Syft, SBOM, NVD, GitHub Advisory, --fail-on, severity threshold.
Do not use when the toolchain is Trivy - use scanning-docker-images-with-trivy.
domain: cybersecurity
subdomain: container-security
tags:
- grype
- vulnerability-scanning
- container-security
- sbom
- anchore
- supply-chain
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
mitre_attack:
- T1610
- T1611
- T1609
- T1525
- T1195
Scanning Container Images with Grype
Overview
Grype is an open-source vulnerability scanner from Anchore that inspects container images, filesystems, and SBOMs for known CVEs. It leverages Syft-generated SBOMs to match packages against multiple vulnerability databases including NVD, GitHub Advisories, and OS-specific feeds.
When to Use
- When conducting security assessments that involve scanning container images with grype
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- Docker or Podman installed
- Grype CLI installed (
curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin)
- Syft CLI (optional, for SBOM generation)
- Network access to pull vulnerability databases
Core Commands
Install Grype
# Install via script
curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin
# Verify installation
grype version
# Install via Homebrew (macOS/Linux)
brew install grype
Scan Container Images
# Scan a Docker Hub image
grype nginx:latest
# Scan from Docker daemon
grype docker:myapp:1.0
# Scan a local archive
grype docker-archive:image.tar
# Scan an OCI directory
grype oci-dir:path/to/oci/
# Scan a Singularity image
grype sif:image.sif
# Scan a local directory / filesystem
grype dir:/path/to/project
# Default table output
grype alpine:3.18
# JSON output for pipeline processing
grype alpine:3.18 -o json > results.json
# CycloneDX SBOM output
grype alpine:3.18 -o cyclonedx
# SARIF output for GitHub Security tab
grype alpine:3.18 -o sarif > grype.sarif
# Template-based custom output
grype alpine:3.18 -o template -t /path/to/template.tmpl
Filtering and Thresholds
# Fail if vulnerabilities meet or exceed a severity
grype nginx:latest --fail-on critical
# Show only fixed vulnerabilities
grype nginx:latest --only-fixed
# Show only non-fixed vulnerabilities
grype nginx:latest --only-notfixed
# Filter by severity
grype nginx:latest --only-fixed -o json | jq '[.matches[] | select(.vulnerability.severity == "High")]'
# Explain a specific CVE
grype nginx:latest --explain --id CVE-2024-1234
Working with SBOMs
# Generate SBOM with Syft then scan
syft nginx:latest -o spdx-json > nginx-sbom.json
grype sbom:nginx-sbom.json
# Scan CycloneDX SBOM
grype sbom:bom.json
Configuration File (.grype.yaml)
# .grype.yaml
check-for-app-update: false
fail-on-severity: "high"
output: "json"
scope: "squashed" # or "all-layers"
quiet: false
ignore:
- vulnerability: CVE-2023-12345
reason: "False positive - not exploitable in our context"
- vulnerability: CVE-2023-67890
fix-state: unknown
db:
auto-update: true
cache-dir: "/tmp/grype-db"
max-allowed-built-age: 120h # 5 days
match:
java:
using-cpes: true
python:
using-cpes: true
javascript:
using-cpes: false
CI/CD Integration
# GitHub Actions
- name: Scan image with Grype
uses: anchore/scan-action@v4
with:
image: "myregistry/myapp:${{ github.sha }}"
fail-build: true
severity-cutoff: high
output-format: sarif
id: scan
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: ${{ steps.scan.outputs.sarif }}
# GitLab CI
container_scan:
stage: test
image: anchore/grype:latest
script:
- grype ${CI_REGISTRY_IMAGE}:${CI_COMMIT_SHA} --fail-on high -o json > grype-report.json
artifacts:
reports:
container_scanning: grype-report.json
Database Management
# Check database status
grype db status
# Manually update vulnerability database
grype db update
# Delete cached database
grype db delete
# List supported database providers
grype db list
Key Vulnerability Sources
| Source |
Coverage |
| NVD |
CVEs across all ecosystems |
| GitHub Advisories |
Open source package vulnerabilities |
| Alpine SecDB |
Alpine Linux packages |
| Amazon Linux ALAS |
Amazon Linux AMI |
| Debian Security Tracker |
Debian packages |
| Red Hat OVAL |
RHEL, CentOS |
| Ubuntu Security |
Ubuntu packages |
| Wolfi SecDB |
Wolfi/Chainguard images |
Best Practices
- Pin image tags - Always scan specific digests, not
latest
- Fail on severity - Set
--fail-on high or critical in CI gates
- Use SBOMs - Generate SBOMs with Syft for reproducible scanning
- Suppress false positives - Use
.grype.yaml ignore rules with documented reasons
- Scan all layers - Use
--scope all-layers to catch vulnerabilities in intermediate layers
- Automate database updates - Keep the vulnerability database current in CI runners
- Compare scans - Track vulnerability count over time for regression detection
Other files in this skill
assets/template.md (verbatim)
Container Image Scan Policy Template
Scan Policy Configuration
Severity Thresholds
| Environment |
Block On |
Alert On |
Accept |
| Production |
Critical, High |
Medium |
Low, Negligible |
| Staging |
Critical |
High, Medium |
Low, Negligible |
| Development |
None |
Critical, High |
Medium, Low, Negligible |
Scan Triggers
Image Inventory
| Image |
Registry |
Tag Policy |
Last Scanned |
Status |
app/frontend |
ghcr.io |
Immutable digest |
YYYY-MM-DD |
Pass/Fail |
app/backend |
ghcr.io |
Immutable digest |
YYYY-MM-DD |
Pass/Fail |
app/worker |
ghcr.io |
Immutable digest |
YYYY-MM-DD |
Pass/Fail |
Grype Configuration Template
# .grype.yaml - Place in repository root
check-for-app-update: false
fail-on-severity: "high"
output: "json"
scope: "squashed"
quiet: false
ignore:
# Template: Add accepted risks below
# - vulnerability: CVE-YYYY-NNNNN
# reason: "Justification for accepting this risk"
# expires: "YYYY-MM-DD" # Optional expiration for risk acceptance
db:
auto-update: true
cache-dir: "/tmp/grype-db"
max-allowed-built-age: 120h
match:
java:
using-cpes: true
python:
using-cpes: true
javascript:
using-cpes: false
stock:
using-cpes: true
Vulnerability Risk Acceptance
| Field |
Value |
| CVE ID |
|
| Severity |
|
| Affected Package |
|
| Image(s) Affected |
|
| Justification |
|
| Compensating Controls |
|
| Approved By |
|
| Approval Date |
|
| Expiration Date |
|
| Severity |
Remediation Timeline |
Escalation |
| Critical |
24 hours |
Security Lead + Engineering VP |
| High |
7 days |
Security Lead |
| Medium |
30 days |
Team Lead |
| Low |
90 days |
Tracked in backlog |
| Negligible |
Best effort |
No escalation |
references/api-reference.md (verbatim)
API Reference: Scanning Container Images with Grype
Grype CLI Commands
| Command |
Description |
grype <image> |
Scan a container image |
grype <image> -o json |
JSON output for parsing |
grype <image> -o sarif |
SARIF output for GitHub Security |
grype <image> --fail-on critical |
Exit non-zero on severity |
grype <image> --only-fixed |
Show only fixable vulns |
grype sbom:<file> |
Scan a pre-generated SBOM |
grype dir:<path> |
Scan a local directory |
grype db status |
Check vulnerability DB status |
grype db update |
Update vulnerability database |
| Source |
Syntax |
Description |
| Registry |
grype nginx:latest |
Pull from registry |
| Docker daemon |
grype docker:myapp:1.0 |
Local Docker image |
| Archive |
grype docker-archive:image.tar |
Saved tar archive |
| OCI dir |
grype oci-dir:path/ |
OCI layout directory |
| SBOM |
grype sbom:bom.json |
CycloneDX/SPDX SBOM |
| Directory |
grype dir:/path/ |
Filesystem scan |
Severity Levels
| Level |
CVSS Range |
Action |
| Critical |
9.0 - 10.0 |
Immediate remediation |
| High |
7.0 - 8.9 |
Fix before deployment |
| Medium |
4.0 - 6.9 |
Plan remediation |
| Low |
0.1 - 3.9 |
Accept or fix later |
| Negligible |
0.0 |
Informational |
Python Libraries
| Library |
Version |
Purpose |
subprocess |
stdlib |
Execute grype CLI |
json |
stdlib |
Parse JSON output |
pathlib |
stdlib |
File path handling |
References
references/standards.md (verbatim)
Standards and References - Container Image Scanning with Grype
Industry Standards
NIST SP 800-190: Application Container Security Guide
- Section 4.1: Image vulnerabilities - Recommends scanning images for known vulnerabilities before deployment
- Section 4.2: Image configuration defects - Covers misconfigurations in container images
- Recommends integrating vulnerability scanning into CI/CD pipelines
CIS Docker Benchmark v1.6
- Rule 4.1: Ensure a user for the container has been created
- Rule 4.6: Add HEALTHCHECK instruction to the container image
- Rule 4.9: Ensure that COPY is used instead of ADD
- Rule 4.10: Ensure secrets are not stored in Dockerfiles
NIST SP 800-53 Rev 5
- RA-5: Vulnerability Monitoring and Scanning
- SI-2: Flaw Remediation
- CM-6: Configuration Settings
- SA-11: Developer Security Testing and Evaluation
OWASP Container Security
- VS-001: Vulnerability Scanning - Scan container images for known vulnerabilities
- VS-002: SBOM Generation - Generate and maintain software bill of materials
- VS-003: Base Image Selection - Use minimal, trusted base images
Vulnerability Databases
CVSS Scoring Reference
| Severity |
CVSS v3.1 Score |
Recommended Action |
| Critical |
9.0 - 10.0 |
Block deployment, immediate remediation |
| High |
7.0 - 8.9 |
Block deployment in production |
| Medium |
4.0 - 6.9 |
Track and remediate within SLA |
| Low |
0.1 - 3.9 |
Accept risk or remediate in next cycle |
| None |
0.0 |
Informational |
Compliance Mappings
PCI DSS v4.0
- Requirement 6.3.1: Identify and manage security vulnerabilities
- Requirement 6.3.3: Update system components to address known vulnerabilities
SOC 2
- CC7.1: To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities
FedRAMP
- RA-5(2): Update the vulnerabilities scanned within every 30 days prior to a new scan
- RA-5(5): Implement privileged access authorization for vulnerability scanning activities
references/workflows.md (verbatim)
Workflow - Container Image Scanning with Grype
Phase 1: Environment Setup
Install Grype and Syft
# Install Grype
curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin
# Install Syft for SBOM generation
curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b /usr/local/bin
# Verify
grype version
syft version
# Create config directory
mkdir -p ~/.grype
# Create configuration file
cat > ~/.grype/.grype.yaml <<EOF
check-for-app-update: false
fail-on-severity: "high"
db:
auto-update: true
cache-dir: "/tmp/grype-db"
max-allowed-built-age: 120h
ignore:
# Add known false positives here
[]
EOF
Phase 2: Image Scanning Workflow
Step 1 - Generate SBOM
syft ${IMAGE_REF} -o spdx-json > sbom.spdx.json
syft ${IMAGE_REF} -o cyclonedx-json > sbom.cdx.json
Step 2 - Run Vulnerability Scan
# Scan directly
grype ${IMAGE_REF} -o json > vulnerability-report.json
# Or scan from SBOM (faster for repeated scans)
grype sbom:sbom.spdx.json -o json > vulnerability-report.json
Step 3 - Evaluate Results
# Count by severity
cat vulnerability-report.json | jq '.matches | group_by(.vulnerability.severity) | map({severity: .[0].vulnerability.severity, count: length})'
# List critical and high findings
cat vulnerability-report.json | jq '[.matches[] | select(.vulnerability.severity == "Critical" or .vulnerability.severity == "High") | {id: .vulnerability.id, severity: .vulnerability.severity, package: .artifact.name, version: .artifact.version, fix: .vulnerability.fix.versions}]'
Step 4 - Gate Decision
# Automated gate check
grype ${IMAGE_REF} --fail-on high
EXIT_CODE=$?
if [ $EXIT_CODE -ne 0 ]; then
echo "GATE FAILED: High or Critical vulnerabilities found"
exit 1
fi
Phase 3: CI/CD Integration
GitHub Actions Complete Workflow
name: Container Security Scan
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Build image
run: docker build -t myapp:${{ github.sha }} .
- name: Generate SBOM
uses: anchore/sbom-action@v0
with:
image: myapp:${{ github.sha }}
format: spdx-json
output-file: sbom.spdx.json
- name: Scan for vulnerabilities
uses: anchore/scan-action@v4
id: scan
with:
image: myapp:${{ github.sha }}
fail-build: true
severity-cutoff: high
output-format: sarif
- name: Upload SARIF to GitHub Security
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: ${{ steps.scan.outputs.sarif }}
- name: Upload SBOM artifact
uses: actions/upload-artifact@v4
with:
name: sbom
path: sbom.spdx.json
Generate Human-Readable Report
# Table output with full details
grype ${IMAGE_REF} -o table > scan-report.txt
# Generate custom HTML report using template
grype ${IMAGE_REF} -o template -t report.tmpl > report.html
- Review critical/high findings from scan output
- Check if fix versions are available (
fix.versions in JSON output)
- Update base image to latest patched version
- Update application dependencies
- Rebuild and rescan to verify remediation
- Add accepted risks to
.grype.yaml ignore list with documented justification
Phase 5: Continuous Monitoring
Scheduled Rescans
# GitHub Actions scheduled scan
name: Scheduled Vulnerability Scan
on:
schedule:
- cron: '0 6 * * 1' # Every Monday at 6 AM
jobs:
rescan:
runs-on: ubuntu-latest
steps:
- name: Scan production images
run: |
for image in $(cat image-inventory.txt); do
grype ${image} --fail-on critical -o json > "report-$(echo $image | tr '/:' '-').json"
done
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.