Sign inSign up
Grype

dhi.io/grype

Grype 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips, 0-alpine3.24-fips, 0.120-alpine-fips, 0.120-alpine3.24-fips, 0.120.1-alpine-fips, 0.120.1-alpine3.24-fips

Index digest:

sha256:380b4cf28fda50c2132bc23a2ddfc67a84c84483484b6c417b2f47906099b1ac

Manifest digest:

sha256:e0c1b0c370c92945533c3f599710f06713dd5866032223a185f439e546805f65

Size

30.18 MB

Last pushed

16 hours ago

Vulnerabilities

1
3
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:79368df23585721edc6ba22afbdec61a81aa7f89e57c2fb69fbd662dd6a9cfe7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:5fe9e03bade3f5c0ab219d18617c5de8f7584a7b02a0815196ba970a6801aeee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grype@sha256:7453b06edf1536932e4acea5bae4aa1f50dcd89d5893129989dfe453d3833f7f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:5e858713278ff3fcf9386467248fef7b395d1a05386ab3a7307e3047ae8d2c2d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grype@sha256:553ebc30f84cc110357c55d5e7ff57cb6c8d9146d704c7e846d197a4741ae9cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:ff7ac8017805d7a10c448bc98fe9c545e4b01947c8e72b823740aeb23b678c7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:0d71b244ccaeade866afaa4b8a5b73177b89b51e8cc0386ee55f99e7e6c6c76a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:551f37e4b6504e92bc5e339114076b5e44503b40f21368499692e79578852029
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:942b1f310aca2c69ad1fb0b7523f1be1283c1383ce1a92ccaed2716ec0b435b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:5e207f7bc1e3212c809cc65f5f5def11bd99d1923c6e2454717773dbc636ec65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:2f70f5484d596b3c63de164db1dd0619cd371b04667c09a216dbc777856ec3a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:495ee2ec01975a3879a6cadd0302a6dfaefa779ee5e295bf148b5a9364105ce1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:83fdfaa570c1ffd2d8585f5bb1b7202494f2ef15b3d5f2e7222fd9f587e14540
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:61795eed183e1950302df9cce9c4c2573cc4c0643281344c468b035b9c01a1ce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:5f13d994b7590c5d32730cd712393bf7e7dc8f044fbbe4ebf4194f8aaa6dd059
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:00959b55d55a77de9895ade9474aeba16fda893c263135d17853c1ed82a707db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:bc43e23c10b8aa9f28db34eaf2818f7652db1eb9a7966f7ec61a8dd62c24c71d