Capabilities

Supported operating systems

A high-level summary of which OS’s are supported

Syft and Grype support several operating systems for package cataloging and vulnerability detection. The table below shows which OS versions are supported and where Grype’s vulnerability data comes from.

Operating SystemSupported VersionsVunnel ProviderData Source
Alpine Linux3.2+, edgealpineAlpine SecDB
Amazon Linux2, 2022, 2023amazonAmazon Linux Security Center
Azure Linux3.0marinerMicrosoft CBL-Mariner OVAL
CentOS5, 6, 7, 8rhelRed Hat Security Data API
Chainguard OSrollingchainguardChainguard Security
Debian7 (wheezy), 8 (jessie), 9 (stretch), 10 (buster), 11 (bullseye), 12 (bookworm), 13 (trixie), 14, unstabledebianDebian Security Tracker
Echo OSrollingechoECHO Security
CBL-Mariner1.0, 2.0marinerMicrosoft CBL-Mariner OVAL
MinimOSrollingminimosMINIMOS Security
Oracle Linux5, 6, 7, 8, 9, 10oracleOracle Linux Security
Raspberry Pi OS7 (wheezy), 8 (jessie), 9 (stretch), 10 (buster), 11 (bullseye), 12 (bookworm), 13 (trixie), 14, unstabledebianDebian Security Tracker
Red Hat Enterprise Linux5, 6, 7, 8, 9, 10
EUS: 5.9, 6.4+, 7, 8.1, 8.2, 8.4, 8.6, 8.8, 9
rhelRed Hat Security Data API
Rocky Linux5, 6, 7, 8, 9, 10rhelRed Hat Security Data API
SUSE Linux Enterprise Server11, 12, 15slesSUSE Security OVAL
Ubuntu12.04 (precise), 12.10 (quantal), 13.04 (raring), 14.04 (trusty), 14.10 (utopic), 15.04 (vivid), 15.10 (wily), 16.04 (xenial), 16.10 (yakkety), 17.04 (zesty), 17.10 (artful), 18.04 (bionic), 18.10 (cosmic), 19.04 (disco), 19.10 (eoan), 20.04 (focal), 20.10 (groovy), 21.04 (hirsute), 21.10 (impish), 22.04 (jammy), 22.10 (kinetic), 23.04 (lunar), 23.10 (mantic), 24.04 (noble), 24.10 (oracular), 25.04 (plucky), 25.10ubuntuUbuntu CVE Tracker
WolfirollingwolfiWolfi Security
Last modified November 26, 2025: allow local too invocation (d20d613)