Sign inSign up
Cosign

dhi.io/cosign

Cosign 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips-dev, 3.1-alpine3.23-fips-dev, 3.1.3-alpine3.23-fips-dev

Index digest:

sha256:58d1208c8b223b4e2d5cde205927204e4557db9d3470bad14e73944e71b33ca3

Manifest digest:

sha256:c7f054f516cabd8f25d1daeca3890e6bad05fcb0c8aa5555e9e3c1f6536c442d

Size

54.53 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cosign:3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cosign:3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cosign@sha256:b075922e84683f55a0ade8a32b99099ac5c99db7c90804b4955c2385b3d1d3b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cosign@sha256:ffe97befb89ac5e9bb979a6add72271eeac90bdcda71daaec4b6827065fd7c1e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cosign@sha256:fa46a560a3c1401f14f899870e78aab52423fe453dbda5819d695ebc09e5d883
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cosign@sha256:93eb503dc863fc37bd9a3a1e1c5b5873b53ddefb2fa0c38a18451baa169fd081
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cosign@sha256:0298b6cb76ca67010cf9ec034badd2953e3f79b859fe663e794ef30ddb6c988b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cosign@sha256:c41f2096c381fc881b0d46128888a7b7b209f805daddc5c4832688ac70759e7d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cosign@sha256:ece94aa82cabc3d242bfcc8c7e6f8a43b177826add72a39e0c8392f1d4245b30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cosign@sha256:12e2f8c9f20957e53e582f001cb8bffc54ed570a65595fb6dd47be2a3aa9bde7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cosign@sha256:6c951e971196b11414a37d572785d1773cd74d2878542646d72f9eafb1adeee4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cosign@sha256:5688bf07604548faa07686049300934c55c16d738f3938d9812523657257d584
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cosign@sha256:5ca36788e297199d5ea7e37e8c59a5b3d274ed3b945aa833d5103c1df9aa6247
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cosign@sha256:c81013f4580df296135b69835a8930101cce63362791f975396c5377aa07e0b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cosign@sha256:75c981a1256662a76ed9a7419beabf27c566d19de3ed12f1bf092f67fda9da85
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cosign@sha256:517532ba07026204ae58fa333b4ee930ae636aa4fa84018d78432c79cef75bcf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cosign@sha256:fc33bf91e1936ad6c515b798e50fcf33f93c7c4b38ebd02b72487b86fca8c891
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cosign@sha256:0010a2ec2044c333df105d560e2e32e34e0ce56df3d1a2f7e99df950c7492939
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cosign@sha256:d5fc4a06f8a444a735582f351ff0b3fa01121eebbcfaa19a11f520b35ec11258