Sign inSign up
Grist

dhi.io/grist

Grist 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.7, 1.7-debian, 1.7-debian13, 1.7.19, 1.7.19-debian, 1.7.19-debian13

Index digest:

sha256:e81cb5f788756a8d94d6b12001d0d423fa2e26d432c4eddc439c7a858be617f6

Manifest digest:

sha256:f1777cb1be4fde7a443adf2ac2f48ae9165eec7ae5d569e81cf4a68dde75515a

Size

169.32 MB

Last pushed

8 hours ago

Vulnerabilities

0
2
26
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grist:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grist:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grist@sha256:0920dbffbc23c85e5214d08f0bea51ee0255a99b35e1e005a448cf03b1bbfba6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grist@sha256:94d2059bc4e93d12fc2cae9fd81c3dcaaceec7748feb1c77cb3b1b981ae7dc67
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grist@sha256:ad76c723a3110c2ba94b207993f0b24cb48e94253f2ef3830d941feae26bc896
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grist@sha256:2935352acd41ed29f81497e2426ba67e1369ab8ba1481afe2c987c39ed1cfcbb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grist@sha256:4263a821ca862ad7fd062ae7c0d28145a1f83e783c2b5c63e432062618bc45d3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grist@sha256:0a2d60da2a49537a073571f29bf213b87e87347d197a0792b246e261571f1a10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grist@sha256:597c7b6d7d621676dcafe4544787a72e9de8d5617f338362377d1470bd48ac48
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grist@sha256:6aec918ecda419c38be9e87ca30b30ef25c8a1abf357a45bdd100695daa4bc07
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grist@sha256:575b61c43722fca41ce2b6824470c660d4861cf67a6ed52925c99aa11cf61405
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grist@sha256:e152b44d9b96182692e1811f7fb0c16b666b8a8c4b00391ef2a0a6f3d6cfe46f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grist@sha256:6a5ee18e61ce33de6b30b0530569a37599208587d3aa7dcc479c4a9d57dc89a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grist@sha256:349f60f129d4d7cd111fd0094227069fb5293ff591df7192e4a10711a4f710a3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grist@sha256:d1fc57ba700d77ded02be79f511f7c16c8e8274e4324ec7f819e51f3befa32cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grist@sha256:aeaae9860bfcd42481a3865b93f6b2479bb40bd60d699ac4673d47b8bdeb2e7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grist@sha256:5e3af738ed28d03cd139ebfb453a5480be657101cc3b1811b1fb73c848bbb089