Sign inSign up
notation

dhi.io/notation

Notation 1.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23, 1.3-alpine3.23, 1.3.2-alpine3.23

Index digest:

sha256:ee8ada8d0a85a891763212a38dffe86a99014187362699c0e0f975271c86f5b5

Manifest digest:

sha256:cf776e4b34a2736b6778d703c850f8b87dff05ef2ec59ab2f31741339d94a9f8

Size

3.77 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:6d875fdfd1f4aa4ffb9c58368ab33a2949ca5dd3dedd55c3987ee129fed715f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:8f74e7dd15306c570bd3628c7e808bfa2e6eaf755374871904012002ca2add07
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:824f9ed3884ac2490e48a90a25e7dd1153321e0e8c8a6f88067f9bae322a5f72
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:e833d1302856989d891b1aa826a5dfe558d68849c50008dbdc77b46146fbeefc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:7dbeec10069622822d39b0cc04df37ba5c171a29e7a246504bdcd5c6ada794f7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:8c908727d2210bc178f8e939088831a48f589674113e36695a641016ebc57c84
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:47427931d92f05c37b1779c20bb8e9e6c1e36a8bd6b3744d5833435910122069
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:a1bda028089bcc5b9ef6e579dcd7b4b09978b32bd6ac518367fdbac567c78e9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:059e8268d0284c9b9951d79a818ff166d2eb47b0d1ef60405ac31abcecbda7aa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:38e8be0778d5d3106600cd0962a29fd6f4bbcee936c509843fb259e29ab8d4c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:8f5436cac100137a857aa51fb3e0c274327faf052fbe1b8cc4c8d9b7862a8bb1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:dc574f39a88b02ba06dbdb3c2d39fd2ab87c8d94cd126f131c161062cd563f99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:353b84b2a054cb927f969bf8d49ea8b6bca1c7b00784f541a5221533693091b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:4f2caa7bd30179a2b9d071ff1cd814c5c3e2b33897a1768eaa3cd03653ed4c88
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:50721e4382220e1eaeed448366f599fc3b112a841e8be3e78c87d4961e4eb948