Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.1307-debian-fips, 1.1307-debian13-fips, 1.1307-fips, 1.1307.2-debian-fips, 1.1307.2-debian13-fips, 1.1307.2-fips

Index digest:

sha256:aff91a0bebb2b969f73a8165e6ad773805fd6f2dd8f6fd5c52ed10b7d2f39169

Manifest digest:

sha256:ab6b48b832441eae97608e3080179628a09520d23e90d091dc7a0cde1b9cc40c

Size

76.26 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:db1ad08e09a05a7f317d30428dbbe6842e1214b30c1312d945ef670a746453f7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:8801edc0f89865bac8948dc8ea663c805c813c12d48f94ce0391b9cdd32a79a0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/snyk@sha256:c58be3f8902350416f204f0317a391c8a1c656468b70a7f9ea15c27339efff57
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:1b74d7dd44202b7628ec82eb4c1d31e2c6ab628d958d125917f5e73b560a055e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/snyk@sha256:539dba291dce5cde342bb45e693208657629cb37d8820a0db791ec2ab5db59df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:ecd7e517682a70885972146a0813a18a7fc1b74a174527dbbf50670797bc8a59
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:fffb496d743f60d79903e3c5171091b020bdfe852a6e350ed83955111a7ff9a1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:1557a8ea119b17ff8350f033be0d72b675f9f6c83ba2d5a902c6f8208822cbe6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:568de6273daf94b0ab49ce3a25755892cc8e08e09f9dec836f0eba829c23db63
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:0a1c317ba1574be2464d4bff071ceb0a3308f91088560f00e84c379527c1803e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:081c91bf7e2fc4937550ff5e1a9ba52798f216f681c25eaf46cf80f079ada963
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:95f324c1d24a411663d55d2339d9ba178ce95ebad33a9f961b91feed5124274a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:a924557a2bb48247ced4788cb5eb194500a9b7c72400247bab4b14c6dca7e043
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:628b10cf13ed9cd9760fa00241889cc4d4cdfb47bcc8b037490982ccc7f57de0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:951c96a29388f7f48a66ef509a328ad1200cddc35e4069e08f4f9092e9524d64
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:8f4e1199627c80462d30342914e1a9d98a34c88f71075c304b80a5dc7cecc8e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:9465a2be535c8d0e2faafa4519b8a0d929491df11931e3563bc3b6249213a5bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:ae084f620093c3cb87d3bcbb1436a0275a054b024f7e50851cd437f8b3c2e7bc