Sign inSign up
Grype

dhi.io/grype

Grype 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.120-alpine3.23-fips-dev, 0.120.0-alpine3.23-fips-dev

Index digest:

sha256:218a43b5ada435d8bc1101a51f6d41e07113aabf59551f2e6476c7cbca59ee24

Manifest digest:

sha256:22163bfad3e96655cbf96f39fc904e528184dd7f2d732e17d54b183fb9325243

Size

54.19 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:09695fac8ac3706fd972cab54f0817e572167cd588d6d427dbac1819b7857a72
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:a1a3867bbce967eb507dffb9f9676312d60a98fc4aaaa0297a60d2ff95d82607
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grype@sha256:ee8082da3230a165be10dfff7d5b32f3c4ac5a0e5f6605eda5fec6032592e99b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:63d481f9f078b9d71e3072e185b878c43879b7f01528671d9518ec5e0d859b05
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grype@sha256:1a92bbc1a425afe6774d8319bec8254ce76c0e82235b6fe706cbc54f9bd09128
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:357948102b6f6fc443a43a7c5e5fb87cc46bb0f75f30b7e9dc2ae13569fe4698
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:0378b933798bdf9f5ef1c9eb88464b43bfcdbee053d34f5e5d20291baee146a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:6a0d100dcfd5a1e2f5c3a2de764c869c3eafff2d3ce82182f689dc4b85c2d9a4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:2313a926806ba81c179719cf37e25dce711c39e13a9611bf1441bbc2f850e6e0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:1723f89533345fadf9aa61f073b8d19f9d82c9b2a6d258507df76e118c52f382
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:75611d344846e78a1ec1712267484ea00115c40adb5bb35087ea1af87738353e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:dee4c81315c27dfc7bcc46dde9f47d2adef60a92fd35b64a85070cda175446d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:0a1b901ec3d9b6c310f62cd5bd8dc2f873f9ff9f3187ff440cb7f4407ae0a1ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:03c8c3b9605e66cabbcf5530781fb31ad112a2f48195272ad4a40ac0fcdadf1b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:5c5d9a4dfb210ff27b279b1a1cc1116e2947de382c3ce0c03bafded1bd7281e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:da1e10f7eaf989c82bf397ccb26db714f5111c934cf8239c9aa4b5a66195dc76
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:e045d348c991b8d902e0c5718f1e3358bba6339b9b54b2e1583d1706752e1db0