linuxserver/sonarr:4.0.20.3014-ls327
SCOUT
F score 0
docker pull linuxserver/sonarr:4.0.20.3014-ls327 click to select Image metadata
PULL COUNT
2.4B
repository-level (not per-tag)
SIZE (COMPRESSED)
87 MB
ARCHITECTURES
2
RUNS AS
root
image config.User
LAST PUSHED
today
2026-10-10 02:37:18
MANIFEST DIGEST
from registry manifest
Latest scan
2026-10-10 06:04:12 UTC · todayOPEN CVES BY SEVERITY
0
CRITICAL
20
HIGH
39
MEDIUM
0
LOW/NEG
Grype DB
2026-10-09T06:32:32.000Z
· rubric cerodeo-v1 RUBRIC BREAKDOWN (6 signals that moved the score)
-200 · High CVEs (fixable) -72 · Medium CVEs (fixable) +10 · Rebuilt in last 90 days +3 · OCI standard labels (≥4) +2 · Multi-arch +2 · readme_has_example
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
Reproduce this score yourself
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.
curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh
./verify-score.sh linuxserver/sonarr:4.0.20.3014-ls327 \
--rubric cerodeo-v1 \
--grype-db 2026-10-09T06:32:32.000Z