Sign inSign up
Grist

dhi.io/grist

Grist 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.19-debian-dev, 1.7.19-debian13-dev, 1.7.19-dev

Index digest:

sha256:871bfabc7991c640fad496ba54760f562db9d05d617d0f962604045472aa29b7

Manifest digest:

sha256:13fdd8ace034528e22f0d1e060fcf9695a8d61bc34637d6e0a6d763ae90d9cb8

Size

216.09 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
26
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grist:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grist:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grist@sha256:a53d9ac25800dbb07e7bfa8bcb79eccc4a4920bcf52752ad5bca3cbbe4c054e8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grist@sha256:3df64bda864a31276b3a8dddba28ca83443b5817634d0e14979a6be816820cdc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grist@sha256:5d41a8cc0b9ff58cb5235ccb8698cccc750297efa5adbadb133ff55c00657da7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grist@sha256:78e0bdc9574d3b4b43108f1a7cc3c15c9c86aba76b6681c735c1609301dbd27d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grist@sha256:936de4c818e1838c237a03e64e560ee5630b00edb3f8c025ef675ef60422a95d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grist@sha256:84130a405e0b97d4b1d9ea45377f287906c30fd73d0ff45235de4180942b8790
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grist@sha256:cdd112a3a457f0788b271797008b6f1de63f264808a3b149b63a11718b8cc090
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grist@sha256:24f9732e778356f8213e884e62dc38d782dd897494118582c4ad6250043f24a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grist@sha256:cc91404d6745609ef8c0474266362a5fc208bed83eb0d86587c790e182980732
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grist@sha256:e346371ab15324d2231eee6a99adbe051d2a201a5f803b3b9c8821c5ac26b9b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grist@sha256:5108a0bafca3380d9bb669803be3237273385ca56136e55887697d6d2584aa29
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grist@sha256:80513b4213df2dd4143aeca70ab46bbc9e05f5f0c3a9d3b362aeb1d90a1275c3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grist@sha256:b05bba804e5457787b923a39c8e41353aa81dc48d0ea855d133219e0a161bcde
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grist@sha256:126f8f5c5892957cdebaa840c43f46f3b8c2d2542c392273cbacc92175db53f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grist@sha256:3054bd35e17990e5fd4114d2eb6883991870a87c963761ad8374df9902c744c4