Sign inSign up
notation

dhi.io/notation

Notation 1.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.3-alpine3.23-dev, 1.3.2-alpine3.23-dev

Index digest:

sha256:58afdc900ecba722f7fa3933c380ba0373e6e14c108ad5a2758f19f2278d5998

Manifest digest:

sha256:a77f688370f7f147cc29c60368f54b5baf6234779d3f0f009e896b29c847c918

Size

10.41 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:76f80111b9d44b91c0a22848c869f0e6e9d9b08310aae0330bacb986cec71208
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:4fb9bb85b22b3def938fb3ee0ca47146936972b8d5bf8681566f3a4fd46009a5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:d934c28c847b5fb7bcbed91fabaa1977961ab09256c28cb57d1e93e07c0978ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:dc3f1a7c92b3f7d6d652855e17c4c3b3df8b92efb69f3c18708d6a69970b7e7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:f93a6f6bb55adbefdc4e9b7684e026d593abed585011ee39ad22e85dcfd63f0a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:310f0daf9936755ec7988f7599f65bfda2f345ae04cba6616452b8f28fd007b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:448080aea742df71c164380cb2efedc61d72b0cd21d50278520693113480931c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:7e0933e74c07a9dc9248271b6d0fdec3c4628f18b614198e0edc9f92dff84150
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:939532b90646e2b77c3d042df0c44291d128153edbc97713380baa85ab097f83
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:5374db82fa6cdd8086793e95af47d5740c22ba4c08fd7cba4480280eb4338855
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:018bdfd7747de6dfe16a74d6403475ed104e46a7f8b6c40c10b4e001b6ff5e40
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:fd8a53ff7377125880a08439b1f3a111e44bdde929c608b8c78c915e1592d60b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:dfda36c012c3148f07ec63752c1c388e8d8e315763f95ed23dd26cfef34efdff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:e42e0d76b034cec4d5bcc70ba5ef943c8430b84f8e59a95c5b355a1de797c83a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:94ef59d10e7f9ca4c4bd9a4886485ab5dee5aa9b14df39a5da5ae50d232f1ed4