dhi.io/chartmuseum
0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.16-alpine-fips-dev, 0.16-alpine3.24-fips-dev, 0.16.6-alpine-fips-dev, 0.16.6-alpine3.24-fips-dev
sha256:17f23e2770c5da81b5f4e3611165dfbe7e77866a33bd96849291025022c242c3
Manifest digest:sha256:45e6ff969cda2a3fa4001ce529b3015335ad54f3d1f1ccbe11575d5e12c7e6cd
Size
23.86 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/chartmuseum:0-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/chartmuseum:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/chartmuseum@sha256:da4345f9147ca63bcf0fbd3779546c9a2c9f7569c1582d508568870a62ee6463 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/chartmuseum@sha256:e4c311e30631b6263826ddbe2885ae8023f680867cdefcb2e10f276967903e4a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/chartmuseum@sha256:049338d4746a81a1695f8d563edf57f5cdde581fbf3ac1e00cd919f780052068 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/chartmuseum@sha256:87e5b5d6222260da478ef5c5e78daf0f6214b5f9083b9cb61b8bce183c707657 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/chartmuseum@sha256:773ca30107babb51d8554fc73bea9a16c08d47e3e8914aa70873ee1a20cd0df2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/chartmuseum@sha256:dfc8089197fe4207105ae7b9e6df18caad99671e3993f5c7bb2d4d4a45715f92 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/chartmuseum@sha256:e3180603ab81763ba177d2507cbd6f75afa2dd22d32b93523ee2770d88427bd8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/chartmuseum@sha256:79d4da80f0490a3c91b4f8fd539b8f69167d9f224b99f048c0e0f5129a4bf98e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/chartmuseum@sha256:732796529bc793f1cf3d31b54dcc9746d9d09c9abdaeebd404cc82cb69b7f828 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/chartmuseum@sha256:490f71fec3e6d33026df0d367970ffda3c624a6653442472caef80429ce8b077 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/chartmuseum@sha256:2725fe43f892c18e2b9f743229db313cc91dc965f65f6d11ace1a5b6ac2a4fe9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/chartmuseum@sha256:14caa805dec91c211edb920ae9917baf6894d97a563069d3fdbd48c2f9fa5a43 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/chartmuseum@sha256:00bac992d2b9b6926543782044784397438b7a1836b8c25075630909fb1b1e7c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/chartmuseum@sha256:f685930fbd49f86d1fa644a65d57ded18bc911cfd0845ea64e9e23add91ba958 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/chartmuseum@sha256:6cae4686714f780d03bd65459a636e10f428404bd0360126699e068370028be0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/chartmuseum@sha256:7458248c9cec7bed3a928e539802ff1a2c131313f8df0cc00a6223e25e9fcd40 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/chartmuseum@sha256:4877f9099dd81cb220a0c6ae48e927b3c8b764e5df46b7d6646445576fda8602 |