dhi.io/build
2-alpine3.23, 2.25-alpine3.23, 2.25.2-alpine3.23
sha256:88ef13b60c795f6297a7767415caa30ec6525a877f80e98561ae6081d3742fd4
Manifest digest:sha256:7e9a5b283ae18abd7dbbc18d7dacaa63e33492e2adf6c8d400126f09dd6fc6ba
Size
17.90 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-alpine3.232. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:b199a71a27122f54b1a1375503a92568dcdd48271a8c1f1a2d50496f64a4c64b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:61476581fcc8abdeb58745940c29c01fb867d581c370c5b7f2a2a921d82a98e3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:117f3c9341bbf254b8e7d4ed8c648bd9ae3068998ca791e86f8e661f566210c6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:e4890cf62e46653467318195e994e5a26ee825c3f931eed7569d479baa32def5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:dec658a16c28a98b40f3400210c73ab670559ee7e4e748994afebe12a44a5b3c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:0efd8b286e18e482e2fdce5c7bfa683f78e5d84a1c2f2e08ea31af3ad1c7dd93 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:2c30b1a57eb1ea9663a93b839ebe69c73d2f948b9d174a3e1412c567ea17ae23 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:3c239ca012c859007c3ac62dc2446cec0a8587ec96c9097f0efe5f8a5da7a56c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:7bb8540176201297a447548dc80bc56f6630119a7f0f15595e2c0bd698a4eac1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:3750f144d557c86e4248fad31545954766c66a428767015b5c707358e40541f7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:dcfd00b7d09c0828b1bfdcabcdb157ea7b9d2d9e8b2df0e7ff30af040bc2cf95 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:3478740f01d7a530749ddd2b48d58b2e253c180f8d76e3e8cdb517d9a7606323 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:389055435d8c8f153f8eccde1a6dcd9f5c77cec8bbed5cba4f0b2fbcaef522c8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:3d54d031d9623c098a8f4cacff22f5e782b6b9a7fed85988d4da6f35e42f962f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:2d33c3a625ab79595640c605078940783a45ca305a8e99d5cc921183a43f9129 |