Sign inSign up
Grype

dhi.io/grype

Grype 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.118-alpine-dev, 0.118-alpine3.24-dev, 0.118.0-alpine-dev, 0.118.0-alpine3.24-dev

Index digest:

sha256:ec9dac668b56aeae2e9342bfdb487fdf9a752fdfd2e2a465dd35af282691e1e9

Manifest digest:

sha256:8856b112db4074bdc27d8c9332e0d98c161158ea011e9dfa7c53e6326d78ff86

Size

53.23 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:5035b4b1cdb9b60c786d5eb652122ec57af803f6620560e17f2d8d641149ba75
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:319a491fd2633593e0a9b396fd63b06cbb67ce2b4754d27ac134ee900009e3ec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:5b07c7a662619a3b082062e8185a6ebd06e72f6ffba722a420b919a664c7bf23
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:811bf21d8b6929d1b9cf49bbc2a3e5da6572196db324a710483bb8ab238bdf68
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:7ac11b0acaf8dda5a9e44f599169852f7b039a1d88b5a3c8f0d7d65fdcdbb706
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:bd57b7df7aabb6e26538e0146255688d9378426b3c06b9d09796dcecfdcc068f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:348fb59bfdf33a4379bcfa276fef83d6e6909d977fef6af624ac29c5fcebbac7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:dbbace8570a677709fefc64bbdd5acace379db08058b6b2be96e16d825914bca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:b017ac4868c040ef28e936241ff565bd02324688fa20c37acd83c18d139f10d3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:e1683ec85a1072a6152cd0ced0fcdc0e036abf18d9d52b1732d78f220ba363dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:7d6f0ab5b183d54462d46a4927150e436d09be23392916c96a2708a942f99a1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:c743fd638d473211f54549530c0685df97decf42f8f2a51a87b3c8d33440b8d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:48f0af7b8057205d2f65099a68e29bb463b94f23bd89a45ee61ae420a402041e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:ac65d97d84ae07f0045b694c4f084a3131a2d118d235bfeacadf2ff9eb05563d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:ae27e91def7cc777493329352cf31cec7be713508fcfd42095348b9a0704a925