How to install grype
Grype is scanner that matches artefacts against vulnerability databases. The project is developed in the open and released under its own licence.
About the project
Grype is scanner that matches artefacts against vulnerability databases. The maintainers own the project, choose releases, and publish their own documentation. This page records a few things worth knowing before you begin.
The project is run by its own contributors rather than by a company. Release cadence, supported platforms and documentation are all decided by the team behind it.
Typical distribution routes
Packaging differs from project to project. Some publish to system repositories, some to their own index, some only as source archives that a build tool expects.
Platform requirements
It is worth checking which platforms the current release targets. Support windows differ, and the newest version is not always the one that fits an older machine.
Once it is in place
A version query afterwards is usually enough to confirm the environment picked it up. If the result is unexpected, the usual causes are a stale path entry or a version manager resolving to a different release.
What this site is
These pages are maintained as reading notes. No project files are stored here.