Sign inSign up
DHI Build

dhi.io/build

DHI Build 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine3.23, 2.25-alpine3.23, 2.25.2-alpine3.23

Index digest:

sha256:88ef13b60c795f6297a7767415caa30ec6525a877f80e98561ae6081d3742fd4

Manifest digest:

sha256:7e9a5b283ae18abd7dbbc18d7dacaa63e33492e2adf6c8d400126f09dd6fc6ba

Size

17.90 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/build:2-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/build:2-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/build@sha256:b199a71a27122f54b1a1375503a92568dcdd48271a8c1f1a2d50496f64a4c64b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/build@sha256:61476581fcc8abdeb58745940c29c01fb867d581c370c5b7f2a2a921d82a98e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/build@sha256:117f3c9341bbf254b8e7d4ed8c648bd9ae3068998ca791e86f8e661f566210c6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/build@sha256:e4890cf62e46653467318195e994e5a26ee825c3f931eed7569d479baa32def5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/build@sha256:dec658a16c28a98b40f3400210c73ab670559ee7e4e748994afebe12a44a5b3c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/build@sha256:0efd8b286e18e482e2fdce5c7bfa683f78e5d84a1c2f2e08ea31af3ad1c7dd93
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/build@sha256:2c30b1a57eb1ea9663a93b839ebe69c73d2f948b9d174a3e1412c567ea17ae23
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/build@sha256:3c239ca012c859007c3ac62dc2446cec0a8587ec96c9097f0efe5f8a5da7a56c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/build@sha256:7bb8540176201297a447548dc80bc56f6630119a7f0f15595e2c0bd698a4eac1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/build@sha256:3750f144d557c86e4248fad31545954766c66a428767015b5c707358e40541f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/build@sha256:dcfd00b7d09c0828b1bfdcabcdb157ea7b9d2d9e8b2df0e7ff30af040bc2cf95
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/build@sha256:3478740f01d7a530749ddd2b48d58b2e253c180f8d76e3e8cdb517d9a7606323
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/build@sha256:389055435d8c8f153f8eccde1a6dcd9f5c77cec8bbed5cba4f0b2fbcaef522c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/build@sha256:3d54d031d9623c098a8f4cacff22f5e782b6b9a7fed85988d4da6f35e42f962f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/build@sha256:2d33c3a625ab79595640c605078940783a45ca305a8e99d5cc921183a43f9129