docker pull linuxserver/lidarr:3.1.0.4875-ls43click to select
Image metadata
PULL COUNT
569.3M
repository-level (not per-tag)
SIZE (COMPRESSED)
123 MB
ARCHITECTURES
2
RUNS AS
root
image config.User
LAST PUSHED
3d ago
2026-10-07 07:41:15
MANIFEST DIGEST
sha256:67887807b13a…
from registry manifest
Latest scan
2026-10-10 05:39:11 UTC · today
OPEN CVES BY SEVERITY
0
CRITICAL
97
HIGH
66
MEDIUM
1
LOW/NEG
Grype DB 2026-10-09T06:32:32.000Z
· rubric cerodeo-v1
RUBRIC BREAKDOWN (7 signals that moved the score)
-300 · High CVEs (fixable) -90 · Medium CVEs (fixable) -201 · High CVEs (no fix) +10 · Rebuilt in last 90 days +3 · OCI standard labels (≥4) +2 · Multi-arch +2 · readme_has_example
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or
massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.