Sign inSign up
Grype

dhi.io/grype

Grype 0.x

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23, 0.120-alpine3.23, 0.120.0-alpine3.23

Index digest:

sha256:d8343bee07e6c0b75916c4ae6ed4019c1930cebd539218f0bb349ecb94b2dedf

Manifest digest:

sha256:0bb9cbb0f8d986770f68b3a7a6fe3396ed5174d4230c9afc6d8cfa80b1b4ee85

Size

26.74 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:c4ed4088f65be4dc940845b85430c7cfd888d09bc034d4ccadacb1bc8ef620ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:76090ab2e57f55f85b45be3cae978ffe5080bf169a954a8525ebd8f56ce92d77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:9b9eae0161ebe4cc5f97d842721aaa8f4f8768ee762171f50e78b6ff9e12ef07
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:0f36857d86692f0fa5f7975afd112797f35ba5f1c4e3f70fd139df20f1e4e667
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:7ff56a673c35d635a3f07acbcf7f309ff83d1fca168f901cca8b2662932c7cee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:74e7633259aea443bb765a57395d866e4d939561d42a7ff221973b2cad8ff663
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:434fc5af02d7df867651d63c6ebd3fb2589a9bbf22bb8b39036912c7b3ee84ec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:815d8c53537a3c2f24b718aed7c76bd4180812587ee2f9f5580ed6a4bf003b26
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:955f7c2ea5ced843a315d4ec32665cfa90bb950b32f185b6d7b2690b68925755
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:3a864fb488b24fd3ab688c4318bf311e47e1da882acf1388a12bab649bf341ed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:9951e7c6284c87291e9d1591cbab47fb24a4e9ea9d728f16e34c85f064af4f2a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:6e3e7e53ab786d8d13a2ed77391baf8939ff5840e4ca788a0b152666c2a2e4e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:92860cb1f8976857fe9f30312f66df5e5f49741a3b99dbd902fc997ce2708dd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:61060e11df4dac7bb24e7ca4a7268bc12e6bd1fb24bc8549c751570e2940d247
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:5ed14e18fe34784fc37fadff3aeb78ae86e2689e74dae680f80843ad2e84da43