How grades on this page work
Each image is scored 0–100 by the cerodeo-v1 Scout rubric. Grade bands:
A ≥ 85 B ≥ 70 C ≥ 55 D ≥ 40 F < 40 .
An image starts at 100 and loses points for open CVEs: −25 per fixable Critical, −10 fixable High, −3 fixable Medium, −8 unfixable Critical, −3 unfixable High. It earns points back for hygiene: non-root default (+10), rebuilt in last 90 days (+10), cosign signature (+5), SLSA provenance (+5), SHA256 pinned (+5), SBOM attestation (+3), HEALTHCHECK (+3), OCI labels (+3), multi-arch (+2–3), upstream GH release (+3), README example (+2).
So an A-grade image means: no critical and few-to-no high fixable CVEs, plus most hygiene signals present. A publisher with many A grades is one that consistently hits both — not just avoiding CVEs by accident, but shipping with signed provenance, non-root defaults, and timely rebuilds. The AVG SCORE above is the average 0–100 Scout score across the 2 scanned images in this namespace.
Full rubric with every weight at /about/grades . Changes to any weight ship as a new rubric_version so old snapshots stay auditable.