Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.grype-ubuntu-24-04-fefbf696-c93f-4834-b035-9bce9c0a5277/image0_logolarge.png

Grype Vulnerability Scanner on Ubuntu 24.04

by cloudimg

Grype vulnerability scanner on Ubuntu 24.04, find known CVEs in container images, filesystems and SBOMs

Grype is a fast, open-source vulnerability scanner from Anchore. From a single command it finds known CVEs in the software you ship, matching the packages it discovers against a regularly updated vulnerability database. It scans container images directly with no Docker daemon required, along with directories, filesystems, archives and git checkouts, and it reads Syft, SPDX and CycloneDX SBOMs so you can scan a bill of materials produced earlier in your pipeline. This cloudimg image runs Grype 0.116.0 on Ubuntu 24.04 LTS, ready to scan the moment you log in.

Grype understands operating-system packages across the major Linux distributions and language dependencies for Java, Python, JavaScript, Ruby, Go, .NET, Rust, PHP and more. Its per-finding severity, fixed-in version and exploit-probability scoring, together with a configurable exit code, make it a natural fit for build pipelines that must fail when a serious vulnerability appears.

The image is built for a fast, reliable start. Grype is installed from the project's official release and verified against the signed checksums before install, and the vulnerability database is pre-downloaded at build time into a shared, system-wide cache so your first scan is instant and works without waiting on a database fetch. The cache location is exported for every shell, and Grype keeps the database current automatically as it ages. There is no listening service and no baked credential: the instance is a self-contained scanning workstation you reach over SSH and point at your images, directories or SBOMs.

Grype is free and open source under the Apache 2.0 licence, with no per-CPU or per-deployment fee. cloudimg is not affiliated with or endorsed by Anchore or the Grype project. cloudimg provides packaging, a checksum-verified install, the pre-cached database, security patching of the base image, and 24/7 support with a guaranteed 24-hour response SLA.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.grype-ubuntu-24-04-fefbf696-c93f-4834-b035-9bce9c0a5277/image3_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.grype-ubuntu-24-04-fefbf696-c93f-4834-b035-9bce9c0a5277/image5_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.grype-ubuntu-24-04-fefbf696-c93f-4834-b035-9bce9c0a5277/image2_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.grype-ubuntu-24-04-fefbf696-c93f-4834-b035-9bce9c0a5277/image6_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies