Sign inSign up
httpbin

dhi.io/httpbin

httpbin 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.2-debian-dev, 0.2-debian13-dev, 0.2-dev, 0.2.3-debian-dev, 0.2.3-debian13-dev, 0.2.3-dev

Index digest:

sha256:ed5aa8d14c99896bc0f52e80a44fa1dde00847a9e39f36646ab9a4de2c4add88

Manifest digest:

sha256:d1f1d0dcd2e37102e88ef2d9612198830e8ca28d1ae68ccfa4ee77ce8146e118

Size

44.17 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpbin:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpbin:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpbin@sha256:8a08ed58d74f3ade0e63cb2745b139196966387bd25a4abef426aaabda3bf36b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpbin@sha256:51329397bf03ca90b73bee6276f6f68b4b32a3c5c002703a6256cb7e0d278874
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpbin@sha256:a97ee66933d000c446d81051b32790ea77006a6548cb43a9fcd4380506c82b35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpbin@sha256:f8c2d35dd78e6acdf3928bab62f9ed13b47fd86eaefde1d2c5d5d367c210a40f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/httpbin@sha256:2ac900df3c2c000be69ad431eb91df0cc332bb5169367d689cc39c4b782e8ef6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpbin@sha256:6ee58b46a7003dce128c521735f3feb8a624a85e38284591a8cfff30d14d6805
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpbin@sha256:0cc5918fa8b9fe6f45cf929103f080364ba17b829be32dba6f7593bd745c6f14
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpbin@sha256:3f6b0ea971604722fa44a9c85e47db938d2233f1688cbf52cfab5a1f9160fdb3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpbin@sha256:cfb7ee8e88e42183b19b2faaa0ea29b374de6388ef481346503f23847acb3fa8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpbin@sha256:738b6cb272d89d58325419d6930d1189ec79fc388882189c37e7fbee458a75c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpbin@sha256:546725698859cbbf017c2a1f4e916aaca393013bca4d7eb886e6b960b80621e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpbin@sha256:56044a0dc5ce8637e3a8a78e1879d5824a6cac2dae44fc7d6dce09aba3138f5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpbin@sha256:d373aec939fbf03be97208cd994706a4617cb1cba35934162d26e5ac4af18c04
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpbin@sha256:caa6f0c2e2c61b1fab203c72c736051e7187d4df15332851ddd3ebffe8100905
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpbin@sha256:4bca44b658a3279c4589b105c2fa1de2a9193a71bb7066da46bebe11d3d124e5