Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.24 Base (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.24-alpine3.24-dev, 3.24-dev

Index digest:

sha256:eb950d88a309a402e2a731ba80bf9067378580becb611aa699ffb87594cd320b

Manifest digest:

sha256:fa8b7c5833edd787eef80ace9e6515ea40f2bc04e41c0edf0950ae594cb9103e

Size

3.40 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.24-alpine3.24-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.24-alpine3.24-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:e1e91063f83fccc230aedc62d67026eef984c8eb9fc2dcd4760f756e85efe805
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:0add974fe828c670aabe00de673df1dbedc8d091d3f642b2f6cd91c63a4c7a90
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:63008bd4e037b1b2fb04d7e03fce72bd6e0fbbd5d37fa865691aad5da767ea89
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:6ff915b50b82fc5484d69ef28a6c65d0e74a4025f0288800635b1f94cb90fe0a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:845d7c483ad61054ed5ed92b89dbc77e9c7ef0aa525c705b641910e49fa5d13f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:9e2a4f267127ab966a7674853c36723f6f07780d4b01de531ca3e0dc0d27d816
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:06b760545c97008875f17441c1787923cc2e65fe75911ba6dc5bf19316b591dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:cec9fd185ab93dcd1389a4ec9d434a45d3a6de993bd661de1aab76e772e1765a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:b896a11a46d89446a8f5262ea2b89b65243c88cacd19dbcbc2884438bd4f4259
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:5161b00a682b9400abed0bca0a4ccf9c9c437d09d863c0eaa2b7c962b46b4b9d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:0d8427802bac32bb5be7c44bc8e557a051a8427c825f81ac922e31fe94233e52
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:f1f583244a8cbb63093d01910e7817acf47c713bd157de39591f5448f00b737d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:474f423ade198b3f06dd1012cc597571937eaea4fa34f8c03847c357ce2c9051
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:1219537e8b7a266611dc4e1361c3c4d4606a9a888214adc14e9f0899746d70ef