How to install grype
Grype is a scanner matching artefacts against vulnerability databases. What follows is background, not a walkthrough. The authoritative version always lives with the project's own team.
Paths onto a machine
In practice this means one of a handful of routes: an operating system package index, a registry tied to a language, a version manager, or a source tree built with the project's own tooling. Which one applies is decided by the platform and by the maintainers.
Who is behind it
Ownership sits with the project's own contributors. Release cadence, supported platforms and documentation are all decided by them, and none of it is mediated here.
Worth confirming early
Check platform support first. Recent work in this space generally assumes a current runtime and a reasonably modern system.
Reading the outcome
Surprises here are rarely the project's fault. Ordering inside the environment decides which copy wins, and that ordering is easy to get wrong.
What this domain is
These pages exist as notes. No files are hosted, and no project material is reproduced on this domain.
Keeping environments clean
Isolating environments, whether with a version manager or per-project directories, removes a whole category of confusing behaviour later on.