Sign inSign up
Grype

dhi.io/grype

Grype 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.120-debian-fips-dev, 0.120-debian13-fips-dev, 0.120-fips-dev, 0.120.1-debian-fips-dev, 0.120.1-debian13-fips-dev, 0.120.1-fips-dev

Index digest:

sha256:146f890410e936c3f29bb876f039b74d45f695aa0208a00070fd5da507b1c779

Manifest digest:

sha256:e8e5ed306cbcd94b8e8c1cd58528688d3d3a38cd897ec955bf7f57a53ee0522c

Size

73.69 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grype:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grype:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grype@sha256:bb6ba8a9238abd36282ae7b400e4a7e65911bb464bb65e189bb58467abdc8a69
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grype@sha256:bdd7457d01889a4e1244455fb13cdc9c956b6cb5d97521f2d749dcd06169b5c9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grype@sha256:8588d10e7df66266b123b0b2a0bd67bfb7b9c711cdbbfc18712d954784dd45a6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grype@sha256:c23178ac745221aecb05c340edf518a689c9058092847e532318efc97e462985
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grype@sha256:065d8a073acaf1dde98654a13e587e1a96cd2e851a90bcbaf2bc79a0f3f38638
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grype@sha256:fa34ed4cbdbd261ce2f7e56fb186f3536d5f7968f25df5d4869affd22b361df9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grype@sha256:236f51ba01a5a4e5b38e7da528c49b99528119dac0f5a6ed5e9a1ab36f833722
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grype@sha256:4ba4ac591159731ebfffb2f299e4c41c32a16397168089f9a4bb56350e7dd43d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grype@sha256:90ffe9c6f0f6986f89e0a65f1f29f6663275f4af15178f70bd2483315124e35a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grype@sha256:ae1ba927653a877478a79fa53a7550c81dfb0b9f41c2b30c90f12442f24fc4ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grype@sha256:1783a66cbe2a0867fdabf5557094648a6409f52d03962b7b93eb54f402fabd85
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grype@sha256:213dcd1ab4e5cfb4aad5e89f9708a2d3d022360d537ddabdd3951606c94d0bd2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grype@sha256:f83e1173629b75849f1d2883dcc162c1a6133fe9d571b346efe13f1767f626fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grype@sha256:b70db431beb25038d02aaeed6f3d4f5ff78f3dacab951014a779ade60270ae41
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grype@sha256:e8e640a7c7b1782641c48fe2060f88562de57452f93142b92c39557465b0b7ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grype@sha256:9d92787f4c87b340a0561228c3ed7d5ebb46c1a3641205a0e151d62fa9378681
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grype@sha256:a960194c343462aa2ab935b559c541263dc34ce664656bfc37d4f12121e1eb4e