Chocolatey Community Coffee Break

Join the Chocolatey Team on our regular monthly stream where we discuss all things Community, what we do, how you can get involved and answer your Chocolatey questions.

Learn More

Chocolatey Product Spotlight

Join the Chocolatey Team on our regular monthly stream where we put a spotlight on the most recent Chocolatey product releases. You'll have a chance to have your questions answered in a live Ask Me Anything format.

Learn More

Announcing Chocolatey Central Management 0.10.0

Livestream from
Thursday, 06 October 2022

We recently released our largest update to Chocolatey Central Management so far. Join Gary and Steph to find out more about Chocolatey Central Management and the new features and fixes we've added to this release.

Watch On-Demand
Chocolatey and Intune Overview

Webinar Replay from
Wednesday, 30 March 2022

At Chocolatey Software we strive for simple, and teaching others. Let us teach you just how simple it could be to keep your 3rd party applications updated across your devices, all with Intune!

Watch On-Demand
Chocolatey For Business. In Azure. In One Click.

Livestream from
Thursday, 9 June 2022

Join James and Josh to show you how you can get the Chocolatey For Business recommended infrastructure and workflow, created, in Azure, in around 20 minutes.

Watch On-Demand
The Future of Chocolatey CLI

Livestream from
Thursday, 04 August 2022

Join Paul and Gary to hear more about the plans for the Chocolatey CLI in the not so distant future. We'll talk about some cool new features, long term asks from Customers and Community and how you can get involved!

Watch On-Demand
Hacktoberfest Tuesdays 2022

Livestreams from
October 2022

For Hacktoberfest, Chocolatey ran a livestream every Tuesday! Re-watch Cory, James, Gary, and Rain as they share knowledge on how to contribute to open-source projects such as Chocolatey CLI.

Watch On-Demand
Chocolatey Product Spotlight: Chocolatey 1.2.0 and Chocolatey Licensed Extension 5.0.0

Livestream from
Thursday, 03 November 2022

Join Paul and Gary for this months Chocolatey product livestream where we look at the latest release of Chocolatey 1.2.0, Chocolatey Licensed Extension 5.0.0 and shine a spotlight on the new hook scripts functionality. This opens up so many possibilities for Chocolatey CLI users!

Watch On-Demand
Chocolatey Coding Livestream

Livestream from
Tuesday, 29 November 2022

Join Josh as he adds the ability to manage Chocolatey GUI config and features with the Chocolatey Ansible Collection.

Watch On-Demand
Introduction into Chocolatey with Veeam

Webinar from
Tuesday, 13 December 2022

Join Gary, Paul, and Maurice as they introduce and demonstrate how to use Chocolatey! Questions will be answered live in an Ask Me Anything format.

Watch On-Demand



Downloads of v 0.73.1:


Last Update:

13 Nov 2023

Package Maintainer(s):

Software Author(s):

  • Anchore Inc


grype docker image scanner cve vulnerability admin


  • 1
  • 2
  • 3

0.73.1 | Updated: 13 Nov 2023



Downloads of v 0.73.1:



Software Author(s):

  • Anchore Inc

Grype 0.73.1

  • 1
  • 2
  • 3

All Checks are Passing

3 Passing Tests

Validation Testing Passed

Verification Testing Passed


Scan Testing Successful:

No detections found in any package files

Learn More

Deployment Method: Individual Install, Upgrade, & Uninstall

To install Grype, run the following command from the command line or from PowerShell:


To upgrade Grype, run the following command from the command line or from PowerShell:


To uninstall Grype, run the following command from the command line or from PowerShell:


Deployment Method:


This applies to both open source and commercial editions of Chocolatey.

1. Enter Your Internal Repository Url

(this should look similar to

2. Setup Your Environment

1. Ensure you are set for organizational deployment

Please see the organizational deployment guide

2. Get the package into your environment

  • Open Source or Commercial:
    • Proxy Repository - Create a proxy nuget repository on Nexus, Artifactory Pro, or a proxy Chocolatey repository on ProGet. Point your upstream to Packages cache on first access automatically. Make sure your choco clients are using your proxy repository as a source and NOT the default community repository. See source command for more information.
    • You can also just download the package and push it to a repository Download

3. Copy Your Script

choco upgrade grype -y --source="'INTERNAL REPO URL'" [other options]

See options you can pass to upgrade.

See best practices for scripting.

Add this to a PowerShell script or use a Batch script with tools and in places where you are calling directly to Chocolatey. If you are integrating, keep in mind enhanced exit codes.

If you do use a PowerShell script, use the following to ensure bad exit codes are shown as failures:

choco upgrade grype -y --source="'INTERNAL REPO URL'" 

Write-Verbose "Exit code was $exitCode"
$validExitCodes = @(0, 1605, 1614, 1641, 3010)
if ($validExitCodes -contains $exitCode) {
  Exit 0

Exit $exitCode

- name: Install grype
    name: grype
    version: '0.73.1'
    state: present

See docs at

chocolatey_package 'grype' do
  action    :install
  source   'INTERNAL REPO URL'
  version  '0.73.1'

See docs at

cChocoPackageInstaller grype
    Name     = "grype"
    Version  = "0.73.1"
    Source   = "INTERNAL REPO URL"

Requires cChoco DSC Resource. See docs at

package { 'grype':
  ensure   => '0.73.1',
  provider => 'chocolatey',
  source   => 'INTERNAL REPO URL',

Requires Puppet Chocolatey Provider module. See docs at

4. If applicable - Chocolatey configuration/installation

See infrastructure management matrix for Chocolatey configuration elements and examples.


Private CDN cached downloads available for licensed customers. Never experience 404 breakages again! Learn more...

Package Approved

This package was approved as a trusted package on 13 Nov 2023.




A vulnerability scanner for container images and filesystems. Easily install the binary to try it out. Works with Syft, the powerful SBOM (software bill of materials) tool for container images and filesystems.


  • Install and uninstall via Chocolatey
  • Supports 64-bit version



choco install grype -y

YAML (Foreman, puppetlabs/chocolatey module)

  ensure: latest
  provider: chocolatey


  ensure: latest

$ErrorActionPreference = 'Stop';

$packageName        = 'grype'
$version            = '0.73.1'
$url64              = ""+$version+"/grype_"+$version+""
$checksum64         = '75d75a7267abd755540cb3be0163d48629356b80b478812e1ef5a7a501c04d17'
$toolsDir           = "$(Split-Path -parent $MyInvocation.MyCommand.Definition)"

$packageArgs = @{
  packageName   = $packageName
  UnzipLocation = $toolsDir
  url64bit      = $url64
  checksumType64= 'sha256'
  checksum64    = $checksum64

Install-ChocolateyZipPackage @packageArgs

Log in or click on link to see number of positives.

In cases where actual malware is found, the packages are subject to removal. Software sometimes has false positives. Moderators do not necessarily validate the safety of the underlying software, only that a package retrieves software from the official distribution point and/or validate embedded software against official distribution point (where distribution rights allow redistribution).

Chocolatey Pro provides runtime protection from possible malware.

Add to Builder Version Downloads Last Updated Status
Grype 0.73.0 87 Friday, November 10, 2023 Approved
Grype 0.72.0 3407 Wednesday, October 25, 2023 Approved
Grype 0.71.0 2248 Tuesday, October 17, 2023 Approved
Grype 0.70.0 243 Monday, October 16, 2023 Approved
Grype 0.69.1 2377 Tuesday, October 3, 2023 Approved
Grype 0.69.0 27 Tuesday, October 3, 2023 Approved
Grype 0.68.1 1478 Monday, September 25, 2023 Approved
Grype 0.68.0 738 Thursday, September 21, 2023 Approved
Grype 0.67.0 501 Friday, September 15, 2023 Approved
Grype 0.66.0 5076 Friday, September 1, 2023 Approved
Grype 0.65.2 2070 Thursday, August 24, 2023 Approved
Grype 0.65.1 3997 Friday, August 11, 2023 Approved
Grype 0.65.0 2209 Tuesday, August 1, 2023 Approved
Grype 0.64.2 2276 Saturday, July 22, 2023 Approved
Grype 0.64.1 1155 Wednesday, July 19, 2023 Approved
Grype 0.64.0 273 Tuesday, July 18, 2023 Approved
Grype 0.63.0 2172 Sunday, July 9, 2023 Approved
Grype 0.62.3 25 Sunday, July 9, 2023 Approved
Grype 0.62.2 7924 Tuesday, June 6, 2023 Approved
Grype 0.62.1 289 Sunday, June 4, 2023 Approved
Grype 0.62.0 33 Saturday, June 3, 2023 Approved
Grype 0.61.1 28 Saturday, June 3, 2023 Approved
Grype 0.61.0 449 Friday, June 2, 2023 Approved
Grype 0.60.0 15301 Wednesday, March 29, 2023 Approved
Grype 0.59.1 50 Monday, March 20, 2023 Approved
Grype 0.59.0 76 Monday, March 6, 2023 Approved
Grype 0.58.0 31 Friday, March 3, 2023 Approved
Grype 0.57.1 32 Friday, March 3, 2023 Approved
Grype 0.57.0 25 Friday, March 3, 2023 Approved
Grype 0.56.0 32 Thursday, March 2, 2023 Approved
Grype 0.55.0 19 Thursday, March 2, 2023 Approved
Grype 0.54.0 32 Wednesday, March 1, 2023 Approved
Grype 0.53.1 16 Wednesday, March 1, 2023 Approved
Grype 0.53.0 35 Tuesday, February 28, 2023 Approved
Grype 0.52.0 19 Tuesday, February 28, 2023 Approved
Grype 0.51.0 25 Tuesday, February 28, 2023 Approved
Grype 0.50.2 213 Monday, November 21, 2022 Approved
Grype 0.50.1 56 Wednesday, October 26, 2022 Approved
Grype 0.50.0 40 Tuesday, October 25, 2022 Approved
Grype 0.49.0 53 Saturday, September 10, 2022 Approved
Grype 0.46.0 45 Wednesday, August 17, 2022 Approved
Grype 0.43.0 34 Saturday, July 23, 2022 Approved
Grype 0.41.0 50 Thursday, July 7, 2022 Approved
Grype 0.40.1 43 Saturday, July 2, 2022 Approved
Grype 0.38.0 50 Sunday, June 5, 2022 Approved

This package has no dependencies.

Discussion for the Grype Package

Ground Rules:

  • This discussion is only about Grype and the Grype package. If you have feedback for Chocolatey, please contact the Google Group.
  • This discussion will carry over multiple versions. If you have a comment about a particular version, please note that in your comments.
  • The maintainers of this Chocolatey Package will be notified about new comments that are posted to this Disqus thread, however, it is NOT a guarantee that you will get a response. If you do not hear back from the maintainers after posting a message below, please follow up by using the link on the left side of this page or follow this link to contact maintainers. If you still hear nothing back, please follow the package triage process.
  • Tell us what you love about the package or Grype, or tell us what needs improvement.
  • Share your experiences with the package, or extra configuration or gotchas that you've found.
  • If you use a url, the comment will be flagged for moderation until you've been whitelisted. Disqus moderated comments are approved on a weekly schedule if not sooner. It could take between 1-5 days for your comment to show up.
comments powered by Disqus