dhi.io/grype
0-alpine-fips, 0-alpine3.24-fips, 0.118-alpine-fips, 0.118-alpine3.24-fips, 0.118.0-alpine-fips, 0.118.0-alpine3.24-fips
sha256:a4c0c054a75c098ad8919d439fefadc9dd83b4242c0f6e98709ce60eef420a26
Manifest digest:sha256:c65408f9084e6cc0121ef4fc656af0d6e271f85a66ede64148a30a62899260bf
Size
30.08 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/grype:0-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/grype:0-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/grype@sha256:4b7b0947b6ef949ab43163bb82b5f2d9d09ac827f8c87eb3947f5e854f61b274 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/grype@sha256:8f4d3d7bb9f74f65105f03064f29b56e8d04e9e3e4683c4b0576558fe9bac57f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/grype@sha256:9b7e8022a8aef0c2e492438647b5fb5bfef9d98aa29a5813f0a5f7dea409a2f3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/grype@sha256:798ccda08bab68c9daa4457b8b173a8a2a5c218d57afb2b634695c3f8f0023dc |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/grype@sha256:e791df0851f66ae38b20374d22813d1358360825267962924668afa44a8a8691 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/grype@sha256:6d992fb66d7d1f0ff4f7fc7e68397ecef440d28b30661f143b66f2b3ff049c26 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/grype@sha256:954fd84363d38d8d3ef91a000ade8a4de0126e375365bcc37e5d03ff2dc476f7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/grype@sha256:125fd999e93e99b79b0214e22d0d370ff76cdfa2af37613bd8aaa1d070bae76e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/grype@sha256:232a7934da629aee355a80d0e4d52d6fff060fa5f0e93339d203da90e0a84929 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/grype@sha256:966b6827adc5c7f45f56fff8b55e0d41b77d7b0c07b65948dd0d57dd9d00fbe1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/grype@sha256:dacaf7980e250d6d6b656b068b57dcb89061d17a5430f4b1d2ee6345b0ea9d04 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/grype@sha256:91fe27d707eadc45bccb2bc5a210686d7a1f88bc03e07802ba1afa8a2daef93f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/grype@sha256:2babf350ddfee42a2c0f94fcb2471eda97656ee4391350008d6f7f4b7d9d2821 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/grype@sha256:f4b70d9d99ff28502a26d49ad0e7caae6e5f1f1e3da74a9f0fd31a0c40f40afd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/grype@sha256:252972af3ea15988e2de43f01e5755688dd1a915c9b0d4baf89aee904b2e0ee0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/grype@sha256:1905560889a1b85c4c06833caf6911d19543e4eff469bdba02f859f2a6ba44ba |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/grype@sha256:9db49098dd6178a19228a759560ca192762c2a3ba020de6b6bb5543547d17a87 |