Sign inSign up
Grype

dhi.io/grype

Grype 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.120-alpine-dev, 0.120-alpine3.24-dev, 0.120.0-alpine-dev, 0.120.0-alpine3.24-dev

Index digest:

sha256:a74aecaff94d5cd993b5a14a5ce122aaeb9bea83a11439020705a28b2f62c9bc

Manifest digest:

sha256:68ad3327631a2457e0303084cd4a974edde0e6aca1a24b3bd88b700bd01ee359

Size

53.38 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:8c1865ec30f67bc04ac4d2d782685ab66924d55f6b311e0bd5eae406bb415577
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:59373184f52752a20a727125540c03606da7deabc7369434dabf0d0354619933
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:5b4c42ee31b1a9495555050c36ef430bd2575a76c500c838268ce1d3ad4cbca0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:07e40ca39e5809d7c68fa443b4771e6c22c537377f0b956da72861e7acf01716
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:1f01a9b5a02f07e875c6a2cf6539cabf8e5b52058d48d46ea137c3387e4799e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:ea85001bb278349aacb7f19130d4c2791397b58a7c5cf3fab57cb099981d2af5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:4b58cd7b76c94282b16b97653c1649456402e96664ce87e258fc52352607fca2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:83b404c501a36a25e3df8790e984f5acbaefd50d4e63e23d7eedefe5e497b580
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:8705d01ce9c2a7817374e6f1074b096db9d72e3003a01b564081db81bb88d296
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:1d5c4c1ebdcf2eca3f5c7bc48e2d4be3a2de2ec1c6e4c1dbe24348103afb1539
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:7a7fa66b5a05e7c6da120471d2a4dc35fec2b92f3e6679fe0f45a88ce21af84a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:2a9d52a79864d7dd145bbe4df50e62eaf8b39cd0af5a38cde71043b5df9b743f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:f62e9d06f14d80e9d476ae2c01a5c88fbcaf48942c1516574870f541768a64e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:93db3d3e688049e06bd1bba9023f7d04b7e04e16d1f05cbfa81a0b190b2dc2c2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:7deb53c5bbafc986cfcb72fb04a804d808a3ec9703655ad37895e157ed3697bb