---
name: escaner-vulnerabilidades-grype
description: Guía experta para usar Grype, el escáner open-source de Anchore que detecta CVEs en imágenes de contenedor, sistemas de archivos y SBOMs. Cubre integración en CI/CD, gestión de falsos positivos y combinación con Syft para generar SBOMs completos.
license: Apache-2.0
metadata:
  id: 1281fdbc
  slug: escaner-vulnerabilidades-grype
  titulo: "Grype — Escáner de Vulnerabilidades en Contenedores"
  servicio: Seguridad
  categoria_recurso: Web-Desarrollo
  tipo: referencia
  nivel: intermedio
  idioma: es
  idioma_original: en
  acceso: gratis
  precio_eur: 0
  plataformas: [CLI, GitHub Actions, Docker, Linux, macOS]
  dependencias: [grype, syft, cosign, docker]
  licencia: { spdx: Apache-2.0, redistribuible: true, uso_comercial: true }
  fuente:
    repo: TerminalSkills/skills
    url: https://github.com/TerminalSkills/skills/tree/main/skills/grype
    commit: 77fa015
    autor: TerminalSkills
    nombre_original: grype
    duplicados_en: []
  seguridad: { veredicto: seguro, riesgo: alto, escaneado: "2026-06-14", motor: "grep-estatico+auditor-llm" }
  ficha:
    que_hace: "Escanea imágenes de contenedor, directorios y SBOMs para detectar vulnerabilidades conocidas (CVEs) e integra los resultados en pipelines CI/CD."
    como_lo_hace: "Utiliza la base de datos de vulnerabilidades de Anchore, ejecuta Grype por CLI o GitHub Action, y genera informes en formatos SARIF, JSON o CycloneDX con umbrales de severidad configurables."
  content_hash: "1281fdbcbf01a25c787888b2737a3648fe1134e99f3c40ab3eb1ac227a23aaf1"
  version: 1.0.0
---

# Grype — Container Vulnerability Scanner


## Overview


Grype, the open-source vulnerability scanner by Anchore that finds known vulnerabilities (CVEs) in container images, filesystems, and SBOMs. Helps developers integrate Grype into CI/CD pipelines, triage findings, and combine it with Syft for SBOM generation.


## Instructions

### Scanning

```bash
# Install
brew install grype

# Scan a container image
grype alpine:3.19
grype nginx:latest
grype ghcr.io/myorg/myapp:v1.2.3

# Scan a local directory
grype dir:./my-project

# Scan a Dockerfile / built image
docker build -t myapp .
grype myapp

# Scan an SBOM (generated by Syft)
syft myapp -o spdx-json > sbom.json
grype sbom:sbom.json

# Fail on severity threshold
grype myapp --fail-on critical          # Exit 1 if critical CVEs found
grype myapp --fail-on high              # Exit 1 if high or critical

# Output formats
grype myapp -o json                     # JSON for CI processing
grype myapp -o table                    # Human-readable (default)
grype myapp -o sarif                    # SARIF for GitHub Security tab
grype myapp -o cyclonedx               # CycloneDX format
```

### CI/CD Integration

```yaml
# .github/workflows/security.yml — Scan images before deployment
jobs:
  vulnerability-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Build image
        run: docker build -t myapp:${{ github.sha }} .

      - name: Generate SBOM
        uses: anchore/sbom-action@v0
        with:
          image: myapp:${{ github.sha }}
          output-file: sbom.spdx.json

      - name: Scan for vulnerabilities
        uses: anchore/scan-action@v4
        id: scan
        with:
          image: myapp:${{ github.sha }}
          fail-build: true
          severity-cutoff: high
          output-format: sarif

      - name: Upload SARIF
        if: always()
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: ${{ steps.scan.outputs.sarif }}
```

### Ignore Known False Positives

```yaml
# .grype.yaml — Configuration and ignore rules
ignore:
  # Ignore specific CVEs (with justification)
  - vulnerability: CVE-2023-12345
    reason: "Not exploitable in our configuration — we don't use affected feature"

  - vulnerability: CVE-2023-67890
    package:
      name: openssl
      version: 3.1.0
    reason: "Patched in our custom build"

  # Ignore all vulnerabilities in test dependencies
  - package:
      location: "**/test/**"

# Only scan for these severity levels
fail-on-severity: high

# DB update settings
db:
  auto-update: true
  validate-age: true
  max-allowed-built-age: 120h          # Re-download if DB is older than 5 days
```

### Combining with Syft

```bash
# Syft generates SBOMs, Grype scans them — powerful combination

# Generate SBOM
syft myapp:latest -o spdx-json > sbom.json

# Scan the SBOM for vulnerabilities
grype sbom:sbom.json -o json > vulnerabilities.json

# Quick pipeline: build → SBOM → scan → sign
docker build -t myapp:v1.2.3 .
syft myapp:v1.2.3 -o spdx-json > sbom.json
grype sbom:sbom.json --fail-on critical
cosign attest --predicate sbom.json --type spdxjson myapp:v1.2.3
```

## Installation

```bash
# macOS
brew install grype

# Linux
curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin

# Docker
docker run anchore/grype:latest myapp:latest
```


## Examples


### Example 1: Setting up Grype for a microservices project

**User request:**

```
I have a Node.js API and a React frontend running in Docker. Set up Grype for monitoring/deployment.
```

The agent creates the necessary configuration files based on patterns like `# Install`, sets up the integration with the existing Docker setup, configures appropriate defaults for a Node.js + React stack, and provides verification commands to confirm everything is working.

### Example 2: Troubleshooting ci/cd integration issues

**User request:**

```
Grype is showing errors in our ci/cd integration. Here are the logs: [error output]
```

The agent analyzes the error output, identifies the root cause by cross-referencing with common Grype issues, applies the fix (updating configuration, adjusting resource limits, or correcting syntax), and verifies the resolution with appropriate health checks.


## Guidelines

1. **Scan in CI/CD** — Run Grype on every build; catch vulnerabilities before they reach production
2. **Fail on high/critical** — Use `--fail-on high` in CI; don't deploy images with known high-severity CVEs
3. **SBOM + scan** — Generate SBOM with Syft, scan with Grype, attach both to the image with Cosign
4. **Ignore with justification** — When ignoring CVEs, document why in `.grype.yaml`; auditors need to see the reasoning
5. **Update the vulnerability DB** — Grype uses a local vulnerability database; ensure it's updated daily in CI
6. **SARIF for GitHub** — Output SARIF format and upload to GitHub Security tab; developers see CVEs inline on PRs
7. **Base image matters** — Most CVEs come from the base image; use minimal bases (distroless, alpine, scratch) to reduce attack surface
8. **Scan running containers** — Periodically scan deployed images; new CVEs are discovered daily against existing packages
