Sign inSign up
Grist

dhi.io/grist

Grist 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.19-debian-dev, 1.7.19-debian13-dev, 1.7.19-dev

Index digest:

sha256:61c2fbf0fc2c02de740303986891625122961ef43ca4112c20cc87ab4cd4e5d6

Manifest digest:

sha256:235b2b4f5739758e70c4f5d415b574058a42686664276ab5d152891466539d08

Size

177.49 MB

Last pushed

10 hours ago

Vulnerabilities

0
2
26
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grist:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grist:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grist@sha256:6f2691464c146e9b90f24a33dce89d5c2912e3891deebfdc89e1bf3be5bf91b1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grist@sha256:fce6acbd6271ae91858a8d76a7b8ed6c3ff731a67d4bc2dec3a013e6d406281b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grist@sha256:8ce53c5bef337aeb11765246e93d66666159452e01008d348c512b3032bcff47
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grist@sha256:5bd28ea74a49502ab6efef9b37407b7b0b6dac05f267b8a1840ee5032775c164
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grist@sha256:a3ae4ee033865abe3752c068f6279988fe93677bb6ee654821257de18b34fd91
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grist@sha256:b744bcb5fcdcd2e195361e30a24a61e7f76c3df66d690e2a5c3c9da36f8a3bd0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grist@sha256:d8be2178339df12464390bbe27db8a24c2d386d1c2ae1a49fb5ba6f9221a4c05
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grist@sha256:64676df57a19d79ced344e8d0acf79219b8248a63561ef0727e4db249f5aea48
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grist@sha256:2568411124f266789ec6a27093192c3234aaa5e32baae2674fabcde4830ea736
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grist@sha256:2dffb824b92a4963ccd24228ff79099b7ab7cdd3f922a81409dde0a85d3c6d00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grist@sha256:79958ff693a0eb650ca4618406b437151b1d0cfcd5a322366c46a00cfb993f8c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grist@sha256:0e1f7410d85f36bf05da180e65a58a9eeb060f86d11f6a7bde12d373282c60c1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grist@sha256:116059af58e1b7ab8c881efc2a25ab231ab50a153a3438dba7d70ec6ff26d608
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grist@sha256:a357821daf6bff29e4ea5d058bc9b3d01ebf1fbd42c73d7965f8fdfd725bb558
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grist@sha256:fdc6c1e30a839e8105261b36155f311c3b662ac2973d5c969cbee9d32829836d