Grype is an open-source scanner that finds known vulnerabilities in container images, filesystems and SBOM documents. It covers operating system packages (Alpine, Ubuntu, Red Hat, Debian) and language dependencies for Java, Python, JavaScript, Ruby, Go, PHP and Rust. The skill adds severity ratings from CVSS, exploit probability from EPSS and CISA Known Exploited Vulnerabilities indicators, and supports table, JSON, SARIF and CycloneDX output.
The core workflow is to identify the target, run grype on it, review CVE IDs and affected packages, prioritize critical and high findings, KEV entries and high EPSS scores, apply fixes and re-scan. In a pipeline, grype runs with a --fail-on threshold after the image build, blocking deployment and alerting the security team on failure and archiving results otherwise. For faster re-scans it can use SBOMs generated by Syft. The folder holds CI config templates, a Grype config, a rule template and reference guides on CVSS, KEV and remediation.