Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.24 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.24-alpine3.24-fips-dev, 3.24-fips-dev

Index digest:

sha256:0ee7d36a61ea9af3905ca4cd3e92fb668125512363acd8905a6dc093353e085d

Manifest digest:

sha256:4b17de43d6e3ae3f167a8e6202f50c55a9658d134e0391503557bd6bf7d4785b

Size

4.23 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.24-alpine3.24-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.24-alpine3.24-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:4ba6075a4387e13bdd9f9acb9240fb1cd2078740fcd80075911653e9bd08d303
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:dc9792ef8adcbbfe33484290c32bb6213181a20202fe4705cff529572eb1f972
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alpine-base@sha256:92bbde745d983c2b504258fb8e9698f812620f6a1fcb801846928cf33090c023
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:80323ab3c2d15517f00734586a598c72d156d8b65d4e25d344f79fb77c77d7aa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alpine-base@sha256:affc27a2a9530f664cff727de402f5b5b9754b584d2b63990fb40ea7d4ff9cbe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:b7975798574c8376285312f6350ecfc29d0b23443ca9e4980f4299979876d523
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:fb363146b4c78af32f6915b04465ee9c53344b03629c2f96e5c1ba8d172feda7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:e5a133b8e721cb5970a7e5ee8f748e83eeaf4f46200f3693d0f2c030b82d070b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:8c9dc27af9b62bbb8448aac7a9f41d3fb20979d6c602ae3456b76e40776b9b3c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:e29f2fb9ed78e3726a44d1c297810d44aa8e2fc6576306740ef9e0b8cdfce76b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:0ebde852a7815679b656883f5754ee1583b8601ad32920ccf6b5560add308d77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:b4476d4962bce9355f2a89fecefaae1b3c45af96e94f34a3c71faab9905570f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:cd8297e22913f342558931abdc2c1a0a02b48f296041bc8b20318a61695b12e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:63f40df6d2591ee96d8cdf9ca9dc0bb598a26d39b3311b90036847bef9d7ba5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:70bb9bb788a48b777ac209d521eaec7fb780966068000acd403b8c23a05076ac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:e279ec1a4dc85a0f5e1107e8e33b4e96b01c68cb38f1476284f1e274f5d40b49