Sign inSign up
Grype

dhi.io/grype

Grype 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips, 0-alpine3.24-fips, 0.118-alpine-fips, 0.118-alpine3.24-fips, 0.118.0-alpine-fips, 0.118.0-alpine3.24-fips

Index digest:

sha256:a4c0c054a75c098ad8919d439fefadc9dd83b4242c0f6e98709ce60eef420a26

Manifest digest:

sha256:c65408f9084e6cc0121ef4fc656af0d6e271f85a66ede64148a30a62899260bf

Size

30.08 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:4b7b0947b6ef949ab43163bb82b5f2d9d09ac827f8c87eb3947f5e854f61b274
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:8f4d3d7bb9f74f65105f03064f29b56e8d04e9e3e4683c4b0576558fe9bac57f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grype@sha256:9b7e8022a8aef0c2e492438647b5fb5bfef9d98aa29a5813f0a5f7dea409a2f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:798ccda08bab68c9daa4457b8b173a8a2a5c218d57afb2b634695c3f8f0023dc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grype@sha256:e791df0851f66ae38b20374d22813d1358360825267962924668afa44a8a8691
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:7b642f4d7cb5f8b159758763a536fe1b29b303ff62f21cf2ab6403a575580f13
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:954fd84363d38d8d3ef91a000ade8a4de0126e375365bcc37e5d03ff2dc476f7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:125fd999e93e99b79b0214e22d0d370ff76cdfa2af37613bd8aaa1d070bae76e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:232a7934da629aee355a80d0e4d52d6fff060fa5f0e93339d203da90e0a84929
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:966b6827adc5c7f45f56fff8b55e0d41b77d7b0c07b65948dd0d57dd9d00fbe1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:dacaf7980e250d6d6b656b068b57dcb89061d17a5430f4b1d2ee6345b0ea9d04
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:91fe27d707eadc45bccb2bc5a210686d7a1f88bc03e07802ba1afa8a2daef93f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:84d00760121fced7e2fa48a6fad3292505bb10a0d769a6d869f6fb8af0515f1a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:f4b70d9d99ff28502a26d49ad0e7caae6e5f1f1e3da74a9f0fd31a0c40f40afd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:252972af3ea15988e2de43f01e5755688dd1a915c9b0d4baf89aee904b2e0ee0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:1905560889a1b85c4c06833caf6911d19543e4eff469bdba02f859f2a6ba44ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:9db49098dd6178a19228a759560ca192762c2a3ba020de6b6bb5543547d17a87