Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.3-alpine-fips-dev, 1.3-alpine3.24-fips-dev, 1.3.4-alpine-fips-dev, 1.3.4-alpine3.24-fips-dev

Index digest:

sha256:af4c515cd1fbe772f5990543fff8fb9a7a5fa56c50b417ff9f735bae82de453f

Manifest digest:

sha256:6c57fc31e697d5eabb9942a91324137c2a7ff4d8cc62b6b44ba3c401551b5a92

Size

12.82 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:2b6c49517a36efc621f939e944dbde5b388668967d46263b4a6df9273a4d8aec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:70082e705de42e51003df9c8f847101b0abc068fe062205ab41d408eac41635c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oras@sha256:7b3e4e5201431d70ed0db1819440b5486aaeb05551bc4ffb12c810859aff3269
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:6a19e1d8479dbb7a1393bcbb1ef0cb49772fad79d7ae10e831b0b14d8d33ef24
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oras@sha256:482cc74a2e24a765b2d85a866ca2f97d6a33a466af68521302ac9a32744b3b3a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:c51d124d66dd1ae687d4968d39cc73ebcaedc54f1a212dd8f8ff51de9ae05171
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:71712c2982946d95528c190420902dce08f8cdd98e94de651c8d9c7f66741581
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:2f28b537ba1b5140ce6b99d37298d961f9fd7aac67358c181ddea533df5019c0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:073dcb0d6d0c95d91162d5c29c2d90f6b7a2a2d925ab53f1f6d4374494f240b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:559be6828c6df80cf58e0b59d198b84de5f6033f87a8f776ad462a761e2604d0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:1d6ffd5ae300f4d4bdc0a2a53a7f70b2f465202f1b0e7e428de2f12e24638759
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:c9d872761e24e4d63a5cdc8ed940b84268cefcc01495a5bc96de7b1759625994
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:992b90b13440c7d9849134843d26483e4e5e65919013a114e0b1ef055bdd158b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:55015aecbe0d542f3218b536d298ad4a9792b03e57bcf1e09707deed6a1f5a6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:afc5cb3a4ce49d1137f258bae37fe109af0f4aa02421efa41c334d314c7e035b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:094cdf2d6aa05cb0301adc2b3b402a959c7021783d628bd3fb3e3f266f429c0a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:1aa58c34afd5943d223fb05d90e6bf1dd34ede8ec782f280ba7436236f218035