This is what is inside the docker container that runs
docker run -it alpine:latest sh
/ # ls -lh /var/lib/apk/
total 0
when i used grype
I use grype to run scan on the alpine docker image
grype alpine:latest
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
libcrypto3 3.1.4-r2 3.1.4-r5 apk CVE-2024-0727 Medium
libcrypto3 3.1.4-r2 3.1.4-r3 apk CVE-2023-6129 Medium
libcrypto3 3.1.4-r2 3.1.4-r4 apk CVE-2023-6237 Unknown
libssl3 3.1.4-r2 3.1.4-r5 apk CVE-2024-0727 Medium
libssl3 3.1.4-r2 3.1.4-r3 apk CVE-2023-6129 Medium
libssl3 3.1.4-r2 3.1.4-r4 apk CVE-2023-6237 Unknown