Sign inSign up
httpbin

dhi.io/httpbin

httpbin 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.2-alpine-dev, 0.2-alpine3.24-dev, 0.2.3-alpine-dev, 0.2.3-alpine3.24-dev

Index digest:

sha256:952a9f22b4ca79ce09e1cf9b3685ef89c454fa098e2e70076298d2ee6de07ab1

Manifest digest:

sha256:e2368444605d92e579b556ec9fb0acdafabe6a12c6955d0e192d76ea2c87d426

Size

31.62 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpbin:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpbin:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpbin@sha256:933e44205771e499abee84034a1e4c20085738a992db91c9a2df36ff87572bec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpbin@sha256:9195582aa07e736d2e0c2d8c6d44b4e4b80cb7e2a64921f06a88ad25f9d5c747
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpbin@sha256:164041df932e2a7b3e6f579ba78c887cc08ed91ddc7a654541399ccb311ac18d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpbin@sha256:9df188709f0663d23c00a49d830cbdd32ad8b8355824961b4f4ec6da65a20fb7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpbin@sha256:4517ca561dac19cd3a8fa271f817f457ca7cbd2610d9112da14d140972966d79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpbin@sha256:a5f326f3613ea96d881ea55938e3e4e9617e7916fa4e8c0c99dea414692c6acc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpbin@sha256:f95ae00109d833b6f056208cd4c0da4c3ffd81e84344b0f07c94ff7186a218bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpbin@sha256:b6e436d837c6fe4a8f00bcb39d9efa02ece501c91a67a9a81e2cdd1b22ffb73b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpbin@sha256:424348729cee4bc0dea3654e985705aaae9449215fa50133aea3589f5e21f353
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpbin@sha256:36abfac6492b3c3682f55440b2cc89d1fe1fe7ec962fac1a6b5237b6bd756e72
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpbin@sha256:4129da99546c9e45b0b45b7376c2f964d0697b16aea1135e708131e6a2f25577
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpbin@sha256:1f18e12698e1ce581c6541ba054cdcf15a94c73f40ade0cc35b97da92e234f55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpbin@sha256:d7951d4377723f93c88636c3d7d7ba59c6e4d1bba08aed8ffe22b7e5e36b5f65
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpbin@sha256:2edfeec8be696f61873a453c283905363fe69a3b3b940a3e175f84542f469f73