dhi.io/notation
1-alpine-fips, 1-alpine3.24-fips, 1.3-alpine-fips, 1.3-alpine3.24-fips, 1.3.2-alpine-fips, 1.3.2-alpine3.24-fips
sha256:0a913a32a0cf99bb93474ee2d497e3592b7f69d7f36fa278e470fe3f1543fe3e
Manifest digest:sha256:3e443c1e3fcce19ea9475b40a1f33d8ec30b75cfa217ef0dc39b60cef2d487a5
Size
7.15 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:15e4168096df41fcb51df32ed824a50d464fbb5435e50a275c2e2fbd1de588c3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:d978a68c01c70fe4323c61362a42ea22d4d2e61a177cc6da175e1cfa84a3d216 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/notation@sha256:3e56e251f48734ed029bbd9b55dd0a697170dfdbbf3ec4142b43692abba9b62a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:2eed72660b0cf7f8cbfc3241ac9d9beae280fd2e55f9c4dc96c7457119aaa9d7 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/notation@sha256:d26b2ae22c0c77ce66aa8f135390dd2fdd6bf8d46331b1bd11a75644b5ce37c8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:12fa4500c69b72ff961feb7abe0b3bd710ffffc8811d253fd11216592a41cfdf |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:d55da004117f8e8774d7fd71eed5f445d3add22cda21345e2a034608bb7795ad |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:a99dd470a257773d1637937c196f703d82ff5af2f385bfbc6c3a4d56bff63da1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:1f8a8c1d16b2de97092d046ba21fc9839b6d05659ad2e82a9f08587dd6ebcba9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:a4bb4829423edc4dc30e432f808f824b4feea7be57d23556e087374612904f91 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:b3936dda21427cff40c474721c25da6834bb0d78de55924958d9b2134af99c41 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:0a24e6add0843d74a96ee517ea923d3b4af1ad7731b78ba91e60833a88b2a05f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:dc82ff3fa4be595781aa8a42636c788222c43042862848acec694003324a64e8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:07c2d220f228262273dce3f3b37a1873e23305d5ec2408fb5b5ad232c04616c6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:784086f4251e67c83cd2fe86fc4add4371dd59f221c93aee3c6a8bc93379a54c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:8d7e9450a46cd00194957682b3b64894e88e6f79883a927c42909b431c1be9e0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:058de24333169363a77b1dfdb250f04e69daa33f26710d2c543420431eb88e72 |