dhi.io/grype
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.118-debian-fips-dev, 0.118-debian13-fips-dev, 0.118-fips-dev, 0.118.0-debian-fips-dev, 0.118.0-debian13-fips-dev, 0.118.0-fips-dev
sha256:967bb06b4abc35b2ef6aed7f6e176810feb6ae98ab82dd05cac9155f0a11ea9d
Manifest digest:sha256:3bd99acfaa4d8de08277ab6a25129ae2833e81f45d541cbf52230555e900da71
Size
73.50 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/grype:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/grype:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/grype@sha256:2c9db792f365d196b699dbec45f32da98b32a6022a9c91d43cbcc5785382713b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/grype@sha256:f25b64a9c55d8ab4502b8b0f97f053b7045c5735f566805b8a2e913b1dbd03b6 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/grype@sha256:e2f544a4c0c1c9a9b205fe2b56fe1fd85227ea1c909fe9eefb9baee4eaa2a514 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/grype@sha256:4f47d9f9db12505617770b5041531647a8818dd94cff085c42ef615d6141e3e3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/grype@sha256:86b974d24f667e1463401fbf7051ef8c9ca91ab32106583370831acfb43a8aaf |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/grype@sha256:ea3acf017a0866741aa15334348be68f55dabb357c36cc6733db4071074988d4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/grype@sha256:473d624017819e025cac5390f18647f79cc64090e0dae06bbb22b7da95b6ba07 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/grype@sha256:538ff56ff96312ca4e000a453483839a952e38f670268d81696f91d778148f77 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/grype@sha256:175f96bebcab9b8a19d7933c807ec38647fc368a611498a2eff62ee75f098345 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/grype@sha256:9b70f30f71136135d84d18e6bb2f5ef71a91cc27afd7d354d574f0087bba1230 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/grype@sha256:88db5ad0e15d30edd9d674a4b3742d9935dc5bf39c8b64b9e40ab11c499af833 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/grype@sha256:369f65501b8c729adc628cebbb8aa1bcd45043249fcee1b43dba2434ccd05d4a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/grype@sha256:c9057d2747373257484d8ca31365dc01dede1b8a2922694049d8abc06d39b887 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/grype@sha256:3a53ab993b8b08ddd15b20aef7105f41268532873fa9c406897422fdc2564f7d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/grype@sha256:ad6d0933350850cdc82ff906267e5be67f4096da6534cc3e599b71e8dbdd18e0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/grype@sha256:653093b923ea9450f0e4c23a8d5f2c7577d8f2cddfc4bd821f677d24ab4d971e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/grype@sha256:b6b39f71193c3d439612563e2242caae4ef17067f575b4f48255b68b0d0a44cf |