Sign inSign up
httpbin

dhi.io/httpbin

httpbin 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.2-alpine, 0.2-alpine3.24, 0.2.3-alpine, 0.2.3-alpine3.24

Index digest:

sha256:6793b7e021a2db9ccb07ba4e8e87c3dbe515843da4d3125f6eea207171d5b90b

Manifest digest:

sha256:9cc8af2b5dd048b8db700b478b1aec8ed0421f39b2c95ddc787399871282a60d

Size

29.69 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpbin:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpbin:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpbin@sha256:14ec6e126cebc10cc83f383713b4bcd877f172173f153f0a228567a315a9fef9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpbin@sha256:b1adaf91daa91e8d7da7a129bc254c162eceb6e204c0dd3ce8c8e15ea4bbbf23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpbin@sha256:7865b7c5c308892f9a7434f2ae7cae46474e1eaa07e241ac29cf7e096f6f5309
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpbin@sha256:35cf1e1bbbaef6dc091fb7871b7640c74bb28b9e35b0b34b6075008bbe002df0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/httpbin@sha256:8be0730254cebc3cc86bde27fd1b43ed4a529882b1783a2c797601ee590753bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpbin@sha256:bfe30168419c497965a5930aa252db1300909faa98c1cc83ce320d4a0fcaf1e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpbin@sha256:ff24ab0377ec1a65db483aba7acc1d4b8c58032baf0f9c20b890155a1578571a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpbin@sha256:4a645cd28e84b7cef69dfb9dd564293184aa45f31f5a1f458f317d3fa4136ea6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpbin@sha256:7313ffd7946585a73334b19eccd6b6e8788a0245a3d68230e9debfb1fce0e088
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpbin@sha256:2f022c02c7486d7bc66fc648d4e644338f2d8f42ef87e93224a8e99503aef8f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpbin@sha256:856533088b89396d605479e33d863dc67863b09b82e9b40aaab5f5a07a2c784d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpbin@sha256:2bcab8b2c83b65d55c0ab264f71e1d08a9fe6c2ab14cb991db86107f5c809145
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpbin@sha256:360c4fd3fb6f3e5bc82e3d216c47464f914cd7003a2fe0b1512094d2a5dd8dc6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpbin@sha256:f15a95406561e5cb1ea2c90ce7c1f74e3e1701433e4cb5af7f781f3840081104
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpbin@sha256:9eb6ea58bd2ae482b0f1cbd60c854720ee81f42e37df25eabe00d076a3a86778