Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.23 Base (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.23-alpine3.23-dev, 3.23-dev

Index digest:

sha256:7a4c92862637be4c84ee086f8a2bc93c6ee9f4cc1913d8fa58c73291deddeb42

Manifest digest:

sha256:7708e2dfdef92a10bc9b7112da3ec156ee481a2fb27f8fd652ac2e9564ac4d97

Size

3.40 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.23-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.23-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:215fbcac4a4c60afd9bb6925bf093bad457f4504c967e4b614e3b897a13fd65a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:02d50300ffa12f3cb27e51fbd8b38083d2b8f0d27a50b4a6e754caffb8e2c751
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:a4d4571fb793da598201fc656807a07902e12f6fd73be7a6c9ff741fa176568b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:64c7eb3680bf0a4b1114b90e76b78f3292e7bc0cfc18b40503c9b63611c15aa7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:fc328b41d44b67c260e2d1d2b17f7b65ccb70cab0a08213d664dc522b735a88b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:1e874dd2343fecdaacd973c0b587ad6b48586e763fced42ce7ad19919c075c18
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:2f9f52695cd3dc3975b2b65be76d185087ea756e0153c78fc02e9584615b3fda
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:79198e12eb1ec814a60a8f0f40d2730e82d229a78fba7597a48239d355bb3745
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:3cd9dbc417c5bd68c197639cee880b2982ea1e28549aebeecfd43d547804b735
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:5fc9b30822a8a25d194e5cf05de83615c016cbd874879b7322372a6485f1a540
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:3e965d7cc1d1561506caae72f52650a2fb8d3fdd05baba42fad8d2f6db354d1b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:dac853343474147ad052cfc31f57ea890ae50bd2ee0a5a235f9907c03105f563
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:8cf913864337ed38a48b7ef5721c0812493dfec4564ea69514d22170b83a3d5f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:7673774f49d3fd2429e36b465dcd7e9fdecac4c42b0c837d8ebe40ac22e259e3