grype · Issues· 402 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #3694
False positives on CPython 3.12.14: missing 3.12 backport for CVE-2026-3644, CVE-2026-4224, CVE-2026-7210
Updated Sep 15, 2026 - #3604
Grype should find and analyze SBOM attestations
enhancementUpdated Sep 10, 2026 - #972
Go mod pseudo-versions may cause false positive results
bugfalse-positiveneeds-investigationUpdated Sep 8, 2026 - #452
Expiry date for ignore rules
enhancementUpdated Sep 8, 2026 - #3245
Split up grype DB into per-provider archives
databaseUpdated Sep 7, 2026 - #3453
Echo OSV feed integration
enhancementUpdated Sep 6, 2026 - #3530
False positive CVE-2025-35036 — hibernate-validator 6.0.23.SP1-redhat-00001 flagged but Red Hat backported the fix
bugUpdated Sep 4, 2026 - #3660
Grype is reporting vulnerability CVE-2026-43500 Ubuntu Kernel Dirty Frag in a fixed kernel
bugUpdated Sep 2, 2026 - #3682
OpenVEX transformer drops Go module namespaces from package handles
Updated Aug 30, 2026 - #3508
grype db search does not properly parse golang PURL
bugUpdated Aug 30, 2026 - #3672
False positive: GHSA-537c-gmf6-5ccf matched against RPM-installed python3-cryptography
bugfalse-positiveUpdated Aug 28, 2026 - #2365
false negative for cpe:2.3:o:linux:linux_kernel:6.6.16:*:*:*:*:*:*:*
bugUpdated Aug 28, 2026 - #3670
Grype misses critical CVEs for vendored libraries owned by unrelated RPMs
bugUpdated Aug 21, 2026 - #3571
Alpine curl version mismatch in findings: Grype reports 8.5.8 while container has 8.21.0-r0 installed
bugneeds-investigationUpdated Aug 19, 2026 - #3491
FALSE NEGATIVE: Recent Tomcat vulnerabilities are not detected (e.g., CVE-2026-43512)
bugfalse-negativenew-data-sourceecosystem:javaUpdated Aug 19, 2026