Sign inSign up
notation

dhi.io/notation

Notation 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.2-debian-dev, 1.3.2-debian13-dev, 1.3.2-dev

Index digest:

sha256:20077648bf1abf5e25bb90e40bb66fb7e6061874a57dd401ffc97f78f9342e63

Manifest digest:

sha256:b7c6fd5951e7b3aa65e308ab0f6fbf2d0607cf813b17697bd17eb1411cb1b5e2

Size

29.73 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:9d43291bf0900f2c22d9c782d9407439b3fce0a1020c0ea464fe8cc81c1a6a88
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:36ea9f9ec371de8cb7e800135eff39d0efbb556f3e7eefe65f0251f80cd9ebb5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:8c9ea4fdb6f31e6e0b6468c9faf20a4cc2660798050a80dfbdc52b8eea773f9e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:f7d743a77f5201feda60b603b8822691c83533000ebf3385bb49570f4724d357
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:78abbf466dbc33486a8d4ebfe1fb92c224a4c724f99ada8d2f647d6e1650fe20
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:ec06da215760c438809116dec5e8cd06ac3b7ff2b3f4e72f6192d1ced4f49935
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:de2f44da819faffbaf558ea6744956c5d510f5a43b42e2c6738916795dd57462
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:a6ccdc8af3af0da32bfa4ba22cc56f85830ed0d9cf03beb923d6f7b4b3195740
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:696d99b41f0e84335ada380d85851d3fba22cbecc151fe92de5b17313629e4bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:445746ec25ec7eb70e14f29f903146e7d7c78242cb06169c142a5ff842814d15
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:dc1a8bfa15cf542c3189f69e5d9090a5bc1d9eeb1200718b9544ecf5e2615f2a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:05580ea7fa25bfe2b6a423b9ae27de21acbacb741c007aa24058a90416aff498
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:d8ffc754ae07e83cd1255768e19101369ad1eb5bde024b4726393a2826b6f25a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:640df311988d832e5908959551b013b74d6f1fc3d5a5d860b4fd848fd736b8a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:b82cc50db46406ca239e1bbe1d1be922262cf28cf78101091ee98b3524e6277f