Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.3-alpine3.23-fips-dev, 1.3.2-alpine3.23-fips-dev

Index digest:

sha256:7ffb3e6a2fdc20a017508628cfcddd1404b0204a066a5cb65799305337c0e8dc

Manifest digest:

sha256:4fb62e020efdaab761a6f23ac686df839d6836b333f37dbf6eab526af6cefd5c

Size

11.24 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:6c97850645428a59adf5e0cc52ffa641d4f71f5b994101b94d601571bb1c36eb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:e1ae2bdcb0cc5c7485821f29e31e8a2ad820d1201c653de4089551d2246ac840
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:80e4808be47ef1b7f5f9d26da964dec869ba2ec2a893e6daeb3bcfe2060d8801
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:dea92a86c0f0c5ee668c8e71132bd17d6572957d543d8b8a76b28ef3b249e7aa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:a36ad58f73cb7d038320ab3dd514a957be0d43a9b2bcc7089ff5577778fb78c0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:25d6aea8f969c2a94f6fb4d257b176a5a267d949008f95b674d230d3e5bc0188
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:80f6d80aac4101760d70de562b243498bbb7050cf07a17941a810a9474e41168
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:f15e93c7ce15e770fe212d2e0ffd06a76d32ba9bbc0c63db7822c570f6aec244
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:325e5e9441d75966425506f4c14c723b2862824ee5c11e5874ec42bc4b61bbbf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:bd3ebfcc335cced6736ffd6e427ab7a3a11e7b931a67464d2fc55fe0dded0c2c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:42c26a5f6015e6e0c8f3ac4da82eb86b26523b66bed4e88a7302d4c999f62ce3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:23658942e1ead0bdfa167ff9364684b493deb2df3ca1c2f4284912b9991fa1ca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:2a710e422394fc5afc10f51613f7f71c0df2461e44a6458c21c93789d0eddd9d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:35f0d220a57b25caae81e8b0b64ff1e09bae78d3a29f18e4dc8e1aae96d523c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:10ecfa183b05ef7e7c125080530784051e927837913d4a991f5aec15ac31abb6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:83d57b47ecb3a437c524ff3e83ebf916e2359ca88968597cf3f3403ea1cf5be3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:18abb7ffbeaa6d10a0531b599f6dc1df0b9352bd654156b901ce4c8bb34073c0