dhi.io/notation
1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.3-alpine-fips-dev, 1.3-alpine3.24-fips-dev, 1.3.2-alpine-fips-dev, 1.3.2-alpine3.24-fips-dev
sha256:c5e3818642445cb3227edce5173dbb8f443a6990d6601cfe0102b5d307bec2f7
Manifest digest:sha256:d33e016398444aa653d181072670af8b00b2feb456dff47fefa8ccfc1f65653a
Size
11.24 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:35f6a901675d4430f31bcc18128182a566cf96d98af2fb95b90ccb6bd0ce47f5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:eb3c21e110454ea636ffb390a8333396b9ecb70aeb70159f035849815cb557ac |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/notation@sha256:e6e1c1d478bcc124c844b5861c8421f56cdec19629fba589dfe83639f09bd216 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:49eb29f7b905897d9d7c30baa67d4b5d3569ffc0e87c5230207c2d6ff464701a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/notation@sha256:47bed1a98e0d58e26de8295fe64ef28fc1101c1d31791b994259af0551069dff |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:29b4a3810d7083673b99b401564dad4eff3c5b36684c8ed70e69ba32ba9de3bb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:1857a6be9d936e132d0b82d48493cad0549c5fdde68b63d31769814846c7775a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:064c3daf2dd62d2149a9be047c02ad061ad3510d7003008a9cd09708d7480ea4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:98a6926226fd33382144439e61911ed9e2d256777723f62b195c1a9be78a6138 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:ca649379901b66262c3dae486d4275f7973d01b227dc9a4183241cfbb775db64 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:48b63b9d2505c99731e15d4bb279c55e2e3dc4f38a48a1cf186300f3b4ee8efb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:2930fc86a7fb670513048ec6c2e2f5e2ca0d5139335bbd278327f6114d1c911b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:154526c4a53cbe87cc1c434c3a0eda76e19749bb7fc5dd4b061fa16d7ef712f9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:cea0eea08bfb1e525aa5b17aec32143136777c706fa29247931ce017da5fe372 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:1f42ae3ae6850e9906ef96b57d5516a087215f0ebd253aad0962d8e6bbeaa349 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:95c5e26e2532626e44bb12d1d59275cdbe6ce33b0f4931b7d06f425476ee610c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:352cbbdf838bf75233e8f8dafa154e2fdf36a7d3bef3747e60491d64e699dc3b |