Sign inSign up
StackHawk MCP Server

dhi.io/stackhawk-mcp

StackHawk MCP Server 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.2-alpine, 1.2-alpine3.24, 1.2.4-alpine, 1.2.4-alpine3.24

Index digest:

sha256:d6720bf2e0fdfc8cf0702a13127a6fe87a8d09b32972609d8c77d0fe9ea8b8b3

Manifest digest:

sha256:2186b58c1d6483de13c4f8c64affab0c171fd7ffc4c8da5b0651cccd7d5f4811

Size

25.81 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/stackhawk-mcp:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/stackhawk-mcp:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/stackhawk-mcp@sha256:e87260e7942c09ff5bf886c4e9ba7330002b4a38122c918d47aa6727fb4ddb23
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/stackhawk-mcp@sha256:af647f94593fdb035631bf67c576d20d78682a247fd14d681caf6a38f72a26b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/stackhawk-mcp@sha256:c3cb8e860c42a6ccd1c5f44dfa82a79a7924b0e2abb3423dac4b7eb37413ac24
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/stackhawk-mcp@sha256:f9ba581882d8b4d01af0df7bbc13c80397a4c34c7a5c109ddc31ddf45e6b7b5c
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/stackhawk-mcp@sha256:deb97991a2fc54e4a5c6d650cc98afc18d075bc2bc1b3acf256cb9d48204748d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/stackhawk-mcp@sha256:85ff76c927ed3b88f2d50b8e9147d88a5671705e1c0b071d96152a0613ec38e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/stackhawk-mcp@sha256:165bff034cbeaf2f138859fe3e53b2384988df9d19e6bb99bb6ec4753ad60d0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/stackhawk-mcp@sha256:6729b9cc1fbaba985697b5363503da7e639dbfb29e75d42b3f90ebf68ca50591
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/stackhawk-mcp@sha256:9cdefdb3d3fa6bb92496cf7de7cdf811e8a332dee1feb644f9d36a4379c758e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/stackhawk-mcp@sha256:9e2c168ded19fbea86ee1f5e7dee974db55e311ca9c8de831e066acca3140d6f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/stackhawk-mcp@sha256:2bef85906222f739324283fd797024cbc8ef316c9997ac47b1d3798cd5cea73c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/stackhawk-mcp@sha256:1ad5ada9a14bd2105ae374796cac2ce2050f9429826b5f03f2fac1631dacab48
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/stackhawk-mcp@sha256:6a948fc9e331598cdfdefaf8b606864bec627dcedf3d3bea6e03d12151283a48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/stackhawk-mcp@sha256:c2223832840229e51fc56dfccb3feaae3a23c264592535aa7302835b6213f744
SPDX SBOMhttps://spdx.dev/Documentdhi.io/stackhawk-mcp@sha256:00fc5b73da634a7b3b1a4018cfafb5a0de832b02e6e022adac7563ab2a2dabfc