1. Images & Charts
  2. grist-fips

Echo is acquiring Minimus. See the announcementfor more details.

grist-fips

grist-fips

Apps
Fips
Stig
Updated 20 hours ago

Risk Reduction

Understand the security benefits of the Minimus image by comparing its vulnerability profile and size to the public image.

Security Posture

Understand how Minimus vulnerability mitigations and compliance configurations secure this image.

Vulnerabilities Comparison

Unique CVE count. Some vulnerabilities may impact multiple packages.

Minimus Image

reg.mini.dev/grist-fips:latest
vs.

Public Image

https://hub.docker.com/layers/gristlabs/grist-oss/latest

Detailed Vulnerability Comparison

Daily report prepared September 25, 2026 at 3:21 AM

CVE
severity
Affected Packages
CVE-2026-48779
high
grist
CVE-2026-4867
high
grist
CVE-2026-12143
high
grist
CVE-2025-65945
high
grist

Size Comparison (MB)

Compressed image sizes for amd64.

Package Count & Risk Comparison

Minimus Image
72 total packages
72 combined OS and application packages
Public Image
1,154 total packages
1,047 packages in additional layers
107 packages in base layer
Color indicates highest severity impacting the package:
critical
high
medium
low
unknown
none
Scale: 1 square = 1 package

Detailed Package Comparison

Report prepared September 25, 2026 at 3:21 AM

Package
version
license
type
Total Vulnerabilities
curl8.14.1-2+deb13u5BSD-3-Clause AND BSD-3-clause AND BSD-4-Clause-UC AND FSFULLR AND GPL-2 AND GPL-2+ AND GPL-3+ AND ISC AND OLDAP-2.8 AND X11 AND curldeb25
libcurl4t648.14.1-2+deb13u5BSD-3-Clause AND BSD-3-clause AND BSD-4-Clause-UC AND FSFULLR AND GPL-2 AND GPL-2+ AND GPL-3+ AND ISC AND OLDAP-2.8 AND X11 AND curldeb25
libc62.41-12+deb13u4BSD-2-clause AND BSD-3-clause-Berkeley AND BSD-3-clause-Carnegie AND BSD-3-clause-Oracle AND BSD-3-clause-WIDE AND BSD-like-Spencer AND BSL-1.0 AND CORE-MATH AND Carnegie AND DEC AND FSFAP AND GPL-2 AND GPL-2+ AND GPL-2+-with-link-exception AND GPL-3 AND GPL-3+ AND IBM AND ISC AND Inner-Net AND LGPL-2 AND LGPL-2+ AND LGPL-2.1 AND LGPL-2.1+ AND LGPL-2.1+-with-link-exception AND LGPL-3 AND LGPL-3+ AND MIT-like-Lord AND PCRE AND SunPro AND Unicode-DFS-2016 AND Univ-Coimbra AND public-domaindeb20
libc-bin2.41-12+deb13u4BSD-2-clause AND BSD-3-clause-Berkeley AND BSD-3-clause-Carnegie AND BSD-3-clause-Oracle AND BSD-3-clause-WIDE AND BSD-like-Spencer AND BSL-1.0 AND CORE-MATH AND Carnegie AND DEC AND FSFAP AND GPL-2 AND GPL-2+ AND GPL-2+-with-link-exception AND GPL-3 AND GPL-3+ AND IBM AND ISC AND Inner-Net AND LGPL-2 AND LGPL-2+ AND LGPL-2.1 AND LGPL-2.1+ AND LGPL-2.1+-with-link-exception AND LGPL-3 AND LGPL-3+ AND MIT-like-Lord AND PCRE AND SunPro AND Unicode-DFS-2016 AND Univ-Coimbra AND public-domaindeb20
dompurify2.5.9(MPL-2.0 OR Apache-2.0)npm16