dhi.io/notation
1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.2-debian-dev, 1.3.2-debian13-dev, 1.3.2-dev
sha256:20077648bf1abf5e25bb90e40bb66fb7e6061874a57dd401ffc97f78f9342e63
Manifest digest:sha256:b7c6fd5951e7b3aa65e308ab0f6fbf2d0607cf813b17697bd17eb1411cb1b5e2
Size
29.73 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:9d43291bf0900f2c22d9c782d9407439b3fce0a1020c0ea464fe8cc81c1a6a88 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:36ea9f9ec371de8cb7e800135eff39d0efbb556f3e7eefe65f0251f80cd9ebb5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:8c9ea4fdb6f31e6e0b6468c9faf20a4cc2660798050a80dfbdc52b8eea773f9e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:a3b4f32cc4d53e35f538b5d3d3a9697893cc59f57805995f4007ef09a5a80282 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:f3c25695fdcccb9b7491bed1461d580e9989a61befd5cf45ecad85704c27679b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:ec06da215760c438809116dec5e8cd06ac3b7ff2b3f4e72f6192d1ced4f49935 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:de2f44da819faffbaf558ea6744956c5d510f5a43b42e2c6738916795dd57462 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:a6ccdc8af3af0da32bfa4ba22cc56f85830ed0d9cf03beb923d6f7b4b3195740 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:696d99b41f0e84335ada380d85851d3fba22cbecc151fe92de5b17313629e4bf |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:445746ec25ec7eb70e14f29f903146e7d7c78242cb06169c142a5ff842814d15 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:4103890bc302de3dee0c06c559df0305ac347d264355170547652d24d15b2367 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:05580ea7fa25bfe2b6a423b9ae27de21acbacb741c007aa24058a90416aff498 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:d8ffc754ae07e83cd1255768e19101369ad1eb5bde024b4726393a2826b6f25a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:640df311988d832e5908959551b013b74d6f1fc3d5a5d860b4fd848fd736b8a8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:b82cc50db46406ca239e1bbe1d1be922262cf28cf78101091ee98b3524e6277f |