Sign inSign up
Grype

dhi.io/grype

Grype 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.118-alpine3.23-fips-dev, 0.118.0-alpine3.23-fips-dev

Index digest:

sha256:d0202bc6609082e11d4a7f4bbe79c23fe62e79c0907587e287481f341d3942e7

Manifest digest:

sha256:9886b947a7556b8438676763adbe5ed8c39c42e940a6f4d8fc9efac9ea851544

Size

54.09 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:879198d7f9d1638752ca35e24ea2941ab878dcdffc40ea2344abeb8e8b2b9db4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:48c43b03f435e19d187ffa8af7f7e7c4b9353cedeac17fbb08462ba7ecb0cc5a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grype@sha256:d1983599fbe55416621f2978537d8ffe4e91ec6fa8df2aaeaa33f9285c308fb0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:996243ebcc4d275fb74839d54e62679ab842640805593b0141502d4296ded0cf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grype@sha256:f13ae8a9f90dce859e0118276b957f2441df222467f59b96eb36f595ae8acff8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:075cd1cbc34c7dfaaafd8eb3f8b3cdb021eeecfc33cd5f664ab95e5194f2b54e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:fe5da963ede76e44178ae0429383b5284413dbe799b68ba971270e6348f3ad8f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:510a125ff29fc6d40b0b0071427d2607e78b96427ac161865801076778138341
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:e962006a533de485b7719a4718845aa2ed65f507e98481a0e98723b2443a9fd1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:3874cc819804e73c3ca66fc8f8b3261fbc5a7457ffe36989480f442738754ef4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:e225b0fda1e802572690edf96c51bf8208e6102653623102bfa3e04f92d24b2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:65b1e2f8fb3fec6726aa4160b0d221ba0b3216c964a1b35de57c7842633d2d9f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:5ddfc85678cb86d5a7798e115200ecde8cb6a2a36eb973015d12c3f14a427936
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:a350de8822b894ad9bcde049c84b3aa40b64b6caf6fd1de1991ea65f3239bf99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:9adc5d225ecf7c8003aeb67ed8a48a9c0307e482b02536369a6178eb2c762d29
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:97850e1a27c1064ca06b10844e483ca6db96dbd49db80d702914e26e4247a1fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:e8c31c5f314bf49e5ad4217179cbe7b91308288e07d0788a0061b3ad8cf1e787