dhi.io/chartmuseum
0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.16-alpine-fips-dev, 0.16-alpine3.24-fips-dev, 0.16.6-alpine-fips-dev, 0.16.6-alpine3.24-fips-dev
sha256:8e4a7b5a08a4dd20046e1c4191ea7f3ec7edd78670966f01006fd577a0b583f1
Manifest digest:sha256:d167c279907da3609f53470388554bb9359001fb999c4d10286a939baf97aa91
Size
23.66 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/chartmuseum:0-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/chartmuseum:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/chartmuseum@sha256:ccc0ab7d35a8e616eaa20f7cfcc0c24df8ce454b38e8d9db37201d7172542fec |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/chartmuseum@sha256:6c4c2f7f39f914aa6c25727307a273d93cbe74cd4a2b26b8f73b2ea3736c59bc |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/chartmuseum@sha256:491d88f474777770d8a7c70e0726c3920f28593a41ddb619e85e9a4be5dd4218 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/chartmuseum@sha256:5145d53dfc8b9419a12785f62c390458022c06e7d8e186eb5c61a989f3c8e3a2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/chartmuseum@sha256:1b023b8dab1b9ed8936419c86ee85145919072f3876f3e7886a5117a2f26678f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/chartmuseum@sha256:b759912c0242b6f3a062d043f1059d4fe65a065192e78ad92611fdf1b4fc6444 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/chartmuseum@sha256:0e360c499dbb00336b1a85f10620ec9c6bf3d6c1999dcef148861198577041de |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/chartmuseum@sha256:1b307a840376329654cdf491801aa89793d7a98bf99c1520ab1c5fbbdb41a6c0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/chartmuseum@sha256:8aed36a2d3fa0e99cd5808b74da15504ee92058631d71338d76be40f312d45e0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/chartmuseum@sha256:df4e02ac5bf8c65afe22584a28f0d8ae6ba780513156ffc398a96c72161917c7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/chartmuseum@sha256:692748330daaf59e4f2e318707bf19fa07f03fc3f8a37e507bce56f592098941 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/chartmuseum@sha256:5b6485598b08996ea407102612cbd5d2cc029104702c85dee972f3475effbe12 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/chartmuseum@sha256:6d14df3e70202f55dd20a3769499ac67fcbbbba7e5478dd6c9d0a0fb176da5bd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/chartmuseum@sha256:f4f8f08e89942597e91b2a4794c6a6f8486d0fc30c8c10ef0fbcb0715fa5bcee |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/chartmuseum@sha256:7a7f4c0ff2a0486baf46691f40389a3afe806f78923b6b574ea3fb5efaf59c31 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/chartmuseum@sha256:da912895e81c122d047c115883be6001732bbb51f8c0eaaa4f025af1af37924f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/chartmuseum@sha256:cf24adf98ebb83236c4ac909f3d20687d5bf2c1e78c725e8b41172691f16a4ee |