Sign inSign up
httpbin

dhi.io/httpbin

httpbin 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.2-alpine, 0.2-alpine3.24, 0.2.3-alpine, 0.2.3-alpine3.24

Index digest:

sha256:eb2c739020b4b3b15e77d45f713f422d9915a1ea0e0c9dfe18e28851f7b8c758

Manifest digest:

sha256:39d85215483f595a6778ae30857db78d24a5efc724cdb9304d1b5f62cbd4bfa4

Size

29.69 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpbin:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpbin:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpbin@sha256:04a95fa6e6783e672f8036114f4a07746c57883124a31598c8c60cdcaaac04cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpbin@sha256:7fb5d84d1d35ff5e9f93d2d76a218a8f304325f700de1a0883c77d490d492179
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpbin@sha256:9ee7baa356cc7035d6c36270444066951399c804e0e381753088083786a7762b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpbin@sha256:4009ba9458e15f09c42867e1e09169b9f241f5392498b1741c9ff0cedd56f449
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpbin@sha256:498e2f3d0bd3b625237bd2472de64b2ba6baa0f957cdd43b7a9334b9701262b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpbin@sha256:623d6740fce97019a635e055169448b7d593783cddd930627e785eec8e0eeacd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpbin@sha256:1c1701baf07d65866aee084274049046c70a917dd9cef86cf4e4d8edf91f26ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpbin@sha256:730e2fbffdfee5d64800eecd227c40022555039776305db7ec09607402899a79
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpbin@sha256:ad4641674880072297fc39e7a764acc7a418864cfaa9906b16407aef99d7f85b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpbin@sha256:d125a6575dab3e28c99dd5fc2db78ace3d897ae0a620517ab3dda189a0ee7cfc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpbin@sha256:78fab1182e1c9bc1b262b8926c15e7965901b22f8f003cb787ecd477bc4ed7ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpbin@sha256:cad40ecbab10b6969403d6a54beb7d1b207726da48bc34f5846ce2376c4dbce2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpbin@sha256:204c89d7b1ba052a5a3205b4a55c801d3d08e4e5f00953265eebbae02e6cd8f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpbin@sha256:e951a0b2dc2ef801b7f741f8264d56a0c76e3d6d1758259910306f73b4e67f4e