Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.23 Base

CIS
linux/amd64
alpine 3.23
Tags:

3.23, 3.23-alpine3.23

Index digest:

sha256:b9d3f74989db66757080994a59c89268bd2e72e83b5d4784969addec65ab3530

Manifest digest:

sha256:f6dce37349cb14ffa49f59b6890aa9b7f4950d7e1ebc9fc40a35b00c823f60ae

Size

1.00 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:df1c3c1161824ed028aab98d945695bd940d8006fd1f32d520dcffadafa99242
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:150a215e94c5a63f919ca4992767dd9583d4497f96ad5855ae42e8bac67f6483
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:74f112435e1bf7c3c33f50632660a7728e142b99bc3fe86f83d0f21fd2492c69
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:817dfed6f6b4b4bace9f6a283d9c168c5544706deb0c23e4f431ffdeff156acd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:fdb9a503e247306fd87fbe644e4b4db835eccbf52fc217ba2adf0ea4daa5069a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:8f4d62f139cdd7df81f2b95d7c200d3d3eca60027cf5d69aacc950dd0dcbb9bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:e74c30e5845b0e380ff0b553c4ab4409536acd2d8a75e3a11291e373d6d84cb3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:3f0432f4196a903a6aa1a523ef585a9fe2edb4b56ee48af41524048cc691b316
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:77f97d2300c1d44914f3b2eb0874815c0f1100f10e7fc9a8142b925755ee8ca7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:73fa9c7eaf93e9367552e185509881095225339ad2d322f5330de59b678b2371
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:31b6260e8e184a47bdbcc7df06cd52ebbaacb65a41cb3da4c79f50b0e75886d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:0665fbfe5a02bc664237c90c71bebc0f00f925113ceaf7b0eeab94643a38ded8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:42df5a3b1a1c9bb6463914f91dbc0a73538b92badc8d597a30136bd59ddc0c90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:ff4722db78fcb265e2aa8c98520b16462291064f1559c7dbe6027d8b142df08c