Sign inSign up
Cosign

dhi.io/cosign

Cosign 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.1, 3.1-debian, 3.1-debian13, 3.1.3, 3.1.3-debian, 3.1.3-debian13

Index digest:

sha256:081f0b0c107251081787f4e5e3e090cc975351f92994990119dbc990aa08442f

Manifest digest:

sha256:36515ad5b12cad9ece60fd41e6a061ef5703416affbf4136cc18aa195ea8592f

Size

25.98 MB

Last pushed

11 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cosign:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cosign:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cosign@sha256:045797ce90aa779b63af56fa2412c0655c0de4602afb9604e9da16aff9b713bb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cosign@sha256:14713c08f6371810319bece93c5c104156cbd938cc2be5c5e34eb173ee3841f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cosign@sha256:89219434e9844ff986e3fa720d323e1545ad42267b9986e73b6a8848e7754d8f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cosign@sha256:00aadaeddb940c3a3a99df165b99fa2a7599fc5fa642dc727867940b0537e7df
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cosign@sha256:ef557dd1fc843d09236009049a3e33d2eff42f3b18d86aa4da55e4562748d1e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cosign@sha256:7a2a49f64e4bd6b00449410f3b56fe8f3a74755ebdf00f84a26d2285a66e817c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cosign@sha256:eb42fbb78be2ed6e4b9707a4ed3106ba48dac0e6c90d283b4207e334ac7d2890
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cosign@sha256:590c11c002a02595e546babaeb3ad5f8c4238d937b7004f601f93c80967f9869
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cosign@sha256:7bb273bf74ff5807334a92745cccbef0dff6a6059b6d3317eea2aae032ca1afb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cosign@sha256:24de8a539fd9cd2eef66af6c88927b70c6e86261d71576d270180009dce3730a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cosign@sha256:13d9550e3ee8dd525274ea1e01c447aa6e24c9d49874f157b47eb4e802479ce7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cosign@sha256:d8f273b0354f012f8fd2c26dda568cdd46fe02bf3706bed768d61fd23be59b04
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cosign@sha256:a7cb069968bf69678359dd39e4033d9e9e1af8164d694731befbf9f6bc8e8966
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cosign@sha256:5519f933ce3359581aa72952d1895e111a2c508a731575812edb2cc2827a0fd5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cosign@sha256:ccbb8c06057246c7a0f48ab67a312149dd7b0a62090a3512f08c934c62e6a1e9