dhi.io/notation
1-alpine3.23-fips-dev, 1.3-alpine3.23-fips-dev, 1.3.2-alpine3.23-fips-dev
sha256:7ffb3e6a2fdc20a017508628cfcddd1404b0204a066a5cb65799305337c0e8dc
Manifest digest:sha256:4fb62e020efdaab761a6f23ac686df839d6836b333f37dbf6eab526af6cefd5c
Size
11.24 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:6c97850645428a59adf5e0cc52ffa641d4f71f5b994101b94d601571bb1c36eb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:e1ae2bdcb0cc5c7485821f29e31e8a2ad820d1201c653de4089551d2246ac840 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/notation@sha256:80e4808be47ef1b7f5f9d26da964dec869ba2ec2a893e6daeb3bcfe2060d8801 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:dea92a86c0f0c5ee668c8e71132bd17d6572957d543d8b8a76b28ef3b249e7aa |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/notation@sha256:a36ad58f73cb7d038320ab3dd514a957be0d43a9b2bcc7089ff5577778fb78c0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:25d6aea8f969c2a94f6fb4d257b176a5a267d949008f95b674d230d3e5bc0188 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:80f6d80aac4101760d70de562b243498bbb7050cf07a17941a810a9474e41168 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:f15e93c7ce15e770fe212d2e0ffd06a76d32ba9bbc0c63db7822c570f6aec244 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:325e5e9441d75966425506f4c14c723b2862824ee5c11e5874ec42bc4b61bbbf |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:bd3ebfcc335cced6736ffd6e427ab7a3a11e7b931a67464d2fc55fe0dded0c2c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:42c26a5f6015e6e0c8f3ac4da82eb86b26523b66bed4e88a7302d4c999f62ce3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:23658942e1ead0bdfa167ff9364684b493deb2df3ca1c2f4284912b9991fa1ca |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:2a710e422394fc5afc10f51613f7f71c0df2461e44a6458c21c93789d0eddd9d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:35f0d220a57b25caae81e8b0b64ff1e09bae78d3a29f18e4dc8e1aae96d523c8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:10ecfa183b05ef7e7c125080530784051e927837913d4a991f5aec15ac31abb6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:83d57b47ecb3a437c524ff3e83ebf916e2359ca88968597cf3f3403ea1cf5be3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:18abb7ffbeaa6d10a0531b599f6dc1df0b9352bd654156b901ce4c8bb34073c0 |