Sign inSign up
httpbin

dhi.io/httpbin

httpbin 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.2-alpine, 0.2-alpine3.24, 0.2.3-alpine, 0.2.3-alpine3.24

Index digest:

sha256:4de459f09e97dd202bac37c3342130c65807fddf722a7fadceef8e6bb93e3dd2

Manifest digest:

sha256:62012f6ca0770ee84661a21bdf1dfb3149fe567c410e751789a7019dbb906a51

Size

29.69 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpbin:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpbin:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpbin@sha256:f394058971a26ad4a57a1c1884e7da2a604655a986567a9067fbe5ca04842696
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpbin@sha256:b1f47c2e5cbf2fe7a81afaaca6576959c32917f92c0d8e1b9fc850f1006c77ba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpbin@sha256:e319fd074d7e654dd4dff9854a35f8ce1564a0f9871b5e180860d10fcf00bbe5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpbin@sha256:d5c39495f7bd8459a234f6c9d97e0eabf2dc28a7969e5528af7ec65057613f46
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpbin@sha256:b4f7eae1dfdc66f03594df33155bce0c660845a7b9d6a1cc155a41bdbbd3d690
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpbin@sha256:de238e44af907683bd2308504d80242ff01db8ffb05a4fb485248e0faf7fedb1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpbin@sha256:ab8c9340affc4a2e7c8e58fb02c0f7174e6dab88affcf35d51a6e54625a241e1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpbin@sha256:cc51575ad7ee3c083cf6b890b2deef318f9743a534597fbb14eeeb4c9ff20b49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpbin@sha256:ad4f9c6123338a72a0ecf5546c160a4b7e547bd8b1f4fcd83d0ab892cf697648
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpbin@sha256:0efcc1cbe793f8f78ea76ad7bf945362f26a04340ff27b6e5b64ce0e28a5f569
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpbin@sha256:c48d32cd6df4b64243198d3958a920804fd8c28cffb6ad2c04781033821d7c07
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpbin@sha256:bbaacbe14319d8b2b574e5012f4e337262de7d097ead0cf7cad2c7be192fbc97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpbin@sha256:c25e6812cfca2c61ccadb456e7ac63391550b1d9dc3890fc60d68e5a7587dfd9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpbin@sha256:7f26b165042a6ab74e4841907e5b70b48621c705d4461bc4ef693fe0213bafcc