Sign inSign up
Grype

dhi.io/grype

Grype 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.120-alpine-fips-dev, 0.120-alpine3.24-fips-dev, 0.120.1-alpine-fips-dev, 0.120.1-alpine3.24-fips-dev

Index digest:

sha256:d2cfc0a9a4c508ab956a0b920895e932606935bad90786a6daae3f39eb38376b

Manifest digest:

sha256:17c8ffcb77e51070c53fc3a99daf878068b1c9072b89ffa9290bf1e54ef0a3b7

Size

54.27 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:d3fc972f049285a1f8f9955badb48f9f01e6c5e7d3cc4fa4193f3f534adc735c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:7aaf885ab34d35a860281fd6599a148bdcc74176b68d4ea7b6e69d507c24cb69
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grype@sha256:768508fd6bc90e11a7c421cc5a6dd8030879322d9f75894b4daca498a98644f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:e96fc1dcc2e4ddc1bbada390369902780b8fc03de2ffaa701dc1e1460ce96be1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grype@sha256:dd91192cdf4d90664e99ac3cfcd534eef47f28115d27746f9d0e416750e91e85
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:c2bab7cf00f27ebbe40bd212554615cccc0f1e98a93e17082086de0830313825
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:ae0b2c87d278a132ab55d427c5f30fdfa45075e2b82fad73add8a3ee2359eced
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:13152ef527fed562ad3044ea0a9ace514b789267067d77d6a7c2797e8e8013a4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:9ff369d8f654c345aee1d8121cc21d375b8fcef687182ba1a041e3e2372a9152
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:d73a90e47eeca572affc9736fd84627bd93fb031ca7806d5d861b98adabf57d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:bd91e19f1482be27ba213770c296299b53fb357e068c63a7c3f921ba238cbdbe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:5f96c47ba8a0a85061b0807c00f5fd4e9d9fc300f0498a53fdf7f9f5ffea303d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:703a4467acbcf79c1fa902155f109decaa5f992f395d3cd92c4aef2cb3e02662
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:11051f803a1ebb40e11e4eee00b2331c5a1d12e83bcbe5d407dbc42b42701dd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:c6013b9ca636d1b700fdd64ea5f62a03c132db0ee4b6509b2a3ef4a707d35f23
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:555580bdca29dacbd7c9c2ddc903b52c1aa3378ef32f5c9852caf51a38dfd103
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:6c681310edc08f19f3888196f5cd5ee9b072d5a88f150e979488ba8ffa00c4f8