Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.3-alpine3.23-fips-dev, 1.3.4-alpine3.23-fips-dev

Index digest:

sha256:0f33a39febb6a259f8979769b5515a9a51faf9a7918a44d30d8763c48de27f3b

Manifest digest:

sha256:1e74844870d5c2b4a05718932dd4ea7403ce4b7c0caad280144155b2f65caca5

Size

12.82 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:99de68e015ebdd88080a043724b4a83acd4872cc2f9faa4d9c709fff4fe957cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:8b9b3e05baad104d4f3034279654719e08af3a824f7257e45bd3920d502801b1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oras@sha256:f10bcd68b820d1c65f484ed86bf08988afbf42614d98f2d11b64c10f1768a53c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:9f8c4fc615c198f437b50b1db87ac8d71b87eb561436c713037629b7015107b7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oras@sha256:bb9a4765814311be4a652e857b69051185cdd7df2a6f29107bf8f8805b946a3c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:903ce2d221a6b7a3388cf06ac049a1cdc2c4d9b5c83580a8dfc3032ab56f1445
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:b1d32c2a7af3625403245a78583b8b3dbfe7a14f93238646e968db865d5360e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:cc5658b36e81d9b5db5e128bda00acf0b0cd705415bfdeb8d79e95b653857adf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:e267a2cc950506dac76f651c05db1099241c43154ab1717da98b3cb3397611fe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:636dc5b0371648e36d573f5eb796a35c8420370dddb41e0481053d86ff3cec31
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:3e1c2e58986e036f4a0387a72757b1360ac09ffb8e6c33e067dbe65ed45b6021
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:9c087c8b5d1d8c29ac61cde8a83e8c084bf1bf4da63042ad5d594bd064c016cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:22d94960a632201761c4345b0b37f18f91ea14cb857440b7676c976b32d853e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:3c26c6e7b80a13af11df4c20c5a180ce47e4f49c9b9cc342b78f88d5f22f4090
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:ce21104512afd81f798d021bdc3718398287610907c108312150da9880f70090
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:ef7c2ce59a8320806a2c37528c7782308fac33ee4a7db1a1dad24fe1fd873919
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:6f2230e991202d4f84d20bd95f955442d6d1d01177d208ef4ded444131644713