grype Kubernetes, CI & IaC
Shell-less Grype vulnerability scanner, built from source via melange.
Size 86 MB Arch x86_64, aarch64 User nonroot (65532) Updated today Upstream github.com/anchore/grype
Pull this image
docker pull ghcr.io/rtvkiz/minimal-grype:latest docker pull ghcr.io/rtvkiz/minimal-grype:latest-dev The -dev variant adds a shell, package manager and build toolchain. For CI and debugging — not production.
Details
- Repository
- ghcr.io/rtvkiz/minimal-grype
- Size (compressed)
- 86 MB
- Built
- 2026-08-13T15:38:22Z (today)
- Architectures
- x86_64, aarch64
- Primary package
- grype
- Entrypoint
- /usr/bin/grype
- User
- nonroot (65532)
- Working dir
- /workspace
- Architectures
- x86_64, aarch64
- Environment
- Labels
-
org.opencontainers.image.title minimal-grype org.opencontainers.image.description Hardened shell-less Grype (vulnerability scanner) built from source via melange with daily CVE patches org.opencontainers.image.url https://github.com/rtvkiz/minimal org.opencontainers.image.source https://github.com/rtvkiz/minimal/tree/main/grype org.opencontainers.image.licenses Apache-2.0
- Entrypoint
- /usr/bin/grype
- User
- nonroot (65532)
- Working dir
- /workspace
- Architectures
- x86_64, aarch64
- Environment
- Labels
-
org.opencontainers.image.title minimal-grype-dev org.opencontainers.image.description Dev variant of minimal-grype: same grype + shell + curl/openssl/dig/jq/git. Not for production. org.opencontainers.image.url https://github.com/rtvkiz/minimal org.opencontainers.image.source https://github.com/rtvkiz/minimal/tree/main/grype org.opencontainers.image.licenses Apache-2.0 dev.minimal.variant dev
| Tag | Pull | Published |
|---|---|---|
| 0.117 | ghcr.io/rtvkiz/minimal-grype:0.117 | 2026-08-14 |
| 0.117.0-r0 | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0 | 2026-08-14 |
| 0.117.0-r0-20260814 | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260814 | 2026-08-14 |
| latest | ghcr.io/rtvkiz/minimal-grype:latest | 2026-08-14 |
| 0.117-dev | ghcr.io/rtvkiz/minimal-grype:0.117-dev | 2026-08-14 |
| 0.117.0-r0-20260814-dev | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260814-dev | 2026-08-14 |
| 0.117.0-r0-dev | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-dev | 2026-08-14 |
| latest-dev | ghcr.io/rtvkiz/minimal-grype:latest-dev | 2026-08-14 |
| 0.117.0-r0-20260813 | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260813 | 2026-08-13 |
| 0.117.0-r0-20260813-dev | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260813-dev | 2026-08-13 |
| 0.117.0-r0-20260812 | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260812 | 2026-08-12 |
| 0.117.0-r0-20260812-dev | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260812-dev | 2026-08-12 |
| 0.117.0-r0-20260811 | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260811 | 2026-08-11 |
| 0.117.0-r0-20260811-dev | ghcr.io/rtvkiz/minimal-grype:0.117.0-r0-20260811-dev | 2026-08-11 |
| 0.116 | ghcr.io/rtvkiz/minimal-grype:0.116 | 2026-08-11 |
| 0.116.1-r0 | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0 | 2026-08-11 |
| 0.116.1-r0-20260811 | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260811 | 2026-08-11 |
| 0.116-dev | ghcr.io/rtvkiz/minimal-grype:0.116-dev | 2026-08-11 |
| 0.116.1-r0-20260811-dev | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260811-dev | 2026-08-11 |
| 0.116.1-r0-dev | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-dev | 2026-08-11 |
| 0.116.1-r0-20260810 | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260810 | 2026-08-10 |
| 0.116.1-r0-20260810-dev | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260810-dev | 2026-08-10 |
| 0.116.1-r0-20260809 | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260809 | 2026-08-09 |
| 0.116.1-r0-20260809-dev | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260809-dev | 2026-08-09 |
| 0.116.1-r0-20260808-dev | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260808-dev | 2026-08-08 |
| 0.116.1-r0-20260808 | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260808 | 2026-08-08 |
| 0.116.1-r0-20260807-dev | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260807-dev | 2026-08-07 |
| 0.116.1-r0-20260807 | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260807 | 2026-08-07 |
| 0.116.1-r0-20260806 | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260806 | 2026-08-06 |
| 0.116.1-r0-20260806-dev | ghcr.io/rtvkiz/minimal-grype:0.116.1-r0-20260806-dev | 2026-08-06 |
14 packages in the image, resolved from the SPDX SBOM.
| Package | Version | License |
|---|---|---|
| alpine/ca-certificates | 20260413 | MPL-2.0 AND MIT |
| ca-certificates-bundle | 20260413-r1 | MPL-2.0 AND MIT |
| ca-certificates-bundle | 20260413-r1 | (MPL-2.0 AND MIT) |
| ca-certificates-bundle | 20260413-r1 | — |
| ca-certificates.yaml | 70f58e72ab3f2139f773ba5c148b573e8d835baa | Apache-2.0 |
| grype-minimal | 0.117.0-r0 | Apache-2.0 |
| grype/melange.yaml | f7373df05a7d1400bd2fd7c965bd213c269b27fd | — |
| sha256:50860d6761f6e217432f80e9de114a5faa828d0f518b95bba16b70713493122d | 20230201 | — |
| sha256:88724dc713cedebf1c49bcc2d6c30069570ba85f368eb0482d7a6286ea900147 | sha256:88724dc713cedebf1c49bcc2d6c30069570ba85f368eb0482d7a6286ea900147 | — |
| wolfi | 20230201 | — |
| wolfi-baselayout | 20230201-r29 | MIT |
| wolfi-baselayout | 20230201-r29 | MIT |
| wolfi-baselayout | 20230201-r29 | — |
| wolfi-baselayout.yaml | 35e7b4713442869116936fae3fe8cf7c69bc9054 | Apache-2.0 |
3 high2 medium 1 fixable
| CVE | Severity | Package | Installed | Fixed in |
|---|---|---|---|---|
| GHSA-rg2x-37c3-w2rh | High | github.com/docker/docker | v28.5.2+incompatible | — |
| GHSA-x744-4wpc-v9h2 | High | github.com/docker/docker | v28.5.2+incompatible | 29.3.1 |
| GHSA-x86f-5xw2-fm2r | High | github.com/docker/docker | v28.5.2+incompatible | — |
| GHSA-pxq6-2prw-chj9 | Medium | github.com/docker/docker | v28.5.2+incompatible | — |
| GHSA-vp62-88p7-qqf5 | Medium | github.com/docker/docker | v28.5.2+incompatible | — |
| GO-2026-5932 | Unknown | golang.org/x/crypto | v0.55.0 | — |
Everything is verifiable without an account. Copy and run:
Build provenance (SLSA L3)
gh attestation verify oci://ghcr.io/rtvkiz/minimal-grype:latest --owner rtvkiz Cosign signature
cosign verify \
--certificate-identity-regexp='https://github.com/rtvkiz/minimal/' \
--certificate-oidc-issuer='https://token.actions.githubusercontent.com' \
ghcr.io/rtvkiz/minimal-grype:latest SBOM attestation (SPDX)
cosign verify-attestation --type spdxjson \
--certificate-identity-regexp='https://github.com/rtvkiz/minimal/' \
--certificate-oidc-issuer='https://token.actions.githubusercontent.com' \
ghcr.io/rtvkiz/minimal-grype:latest \
| jq -r '.payload | @base64d | fromjson | .predicate' Signatures are logged in the public Rekor transparency log.