Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23, 1.3-alpine3.23, 1.3.4-alpine3.23

Index digest:

sha256:e7b6b2abdede7cdb70d2cc82391798ed14c0f5aafb2b40fca50a5047a3432322

Manifest digest:

sha256:f01f1e75c33144b7ad7eb1220024a1c1a117eeec77705eae5866980af48e446c

Size

4.58 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:f41114f37f1f203508fc7a19a7e0961ca995b4d16a8da280441984c1408b42a5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:df6023cce1d36d99375cb65cb36d0a4e4a233f2dddb8d8b231aab55fff96d310
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:c5ca75708df23bd73053673a76148d56c0988ff03cee25bf8358a0dfbfe8a1cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:0c5d64fa9b10fabf71d8bbd50901ad8d3a490928bc9d1308acd9e49cfa413626
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:29a860d51ec5d7f6c15cfa5af68c8afcdd0a33fd02d26c845085241f2a60fa06
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:e74e07edf5bc36ffa19f15f62c13fe712cb0118c6aafb3e8bb9ab821e6a849fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:5bc1435868f86ca602dd02100150e44a071bc0a4c257b7734239f5d5178b90e7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:5cd078d0d35c9634c273c42ceba379524d0d2f50165d47a9946afdf4d4dcc525
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:5252181264598e67099b43e1ca89cef1a388bb3f7537849b19120cab96549f39
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:d67f463f76cd0b79a8247f958a90139136bbb333e2420ac02696028937ff1a49
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:68ef7b6984a5bf19af2eee46d2814de6163040946181e59b54ac1999243fea40
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:8ffbdef11ad1810760a5b4d8f286937c196f202636137fef873c29dfd1226452
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:5697b479043ac8c1cfc87192f5f0468912cc4b38a9e34654ce91308220f48b40
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:dde71b2806647306e95c7c923e2c088c2d449b7934d1f5ca623537754562c7a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:056fd89e8960abef1f6573aedf628c9da507955759516490d2f84e38b0bd69a3