dhi.io/oras
1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.3-alpine-fips-dev, 1.3-alpine3.24-fips-dev, 1.3.4-alpine-fips-dev, 1.3.4-alpine3.24-fips-dev
sha256:ff1c8be0e5a5238ce3206ff3db81163702eb3078d8b754ddbf22a213176d0c5e
Manifest digest:sha256:87f46ba438759d9fa457b3bb61e829da59fbde121779485e887b4225e746fa86
Size
12.83 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/oras:1-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/oras:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/oras@sha256:2c082b04608a02d4fa30173cdd9ca5caddcaedf5037b7e13360724a216b815c6 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/oras@sha256:6b88f9f2287018e970aea1f4c4de9d27ae5ef7b1529db42d85e2a5fbc18b0860 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/oras@sha256:7c1fd2be3340c0a34e9e9c758ea4f77bf767ae2adf66ba2e3cdf880e2d6659a4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/oras@sha256:75d850517b0367eeacac420ad70fca81fc41f14aa74bb66712ed7403007233d4 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/oras@sha256:38b0fa789e4586f726b9a3d9a65959fb83b521fa409256777dea0d551e3ab7e8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/oras@sha256:270456b485006c7fcd43777a85b8d449487056c4918a102ac0133de20c54b794 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/oras@sha256:8b77c9609721148f27bb5cf4b023757e254111a26631e1cc67f8606953b00d88 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/oras@sha256:20030310f374ac65b13d704fc72aef8c7180a5bcbf97878623f3daabed0bd049 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/oras@sha256:ba5d671bdba448faa4e0f3400e8c81603764c952d39b1c3b744cd9b01696d904 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/oras@sha256:7d6d7e4d5268bcb00a5c6d2e8718f7d4b2207e88e518530b5e1da5dcb97c86e9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/oras@sha256:f0c0fdd9638672c2970ddc1a1ed34a61d21171cf6f50384798186c2f0a37eddb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/oras@sha256:5dc1b312f534cbca8f0fed0df52f41a7f8f741c54878a582a8ae5e69d63036b0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/oras@sha256:5d1fddef2229f5e13a591986f55a3a589b4b9cd544621afdf290eca250f73866 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/oras@sha256:bba8592f974cc1840fcc23f42b2e3933818578509c3d03cefc26ff662eec1216 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/oras@sha256:0b3495f733cd7c7c9f41170ed71793be77f672039aebd10de5cd2eb634a213ca |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/oras@sha256:9929639b735ad9f8ce4913ebf86be33fcad9ab6ecd4a6866cc99dd497ed90b98 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/oras@sha256:0785419197c7ece558dbb2a0073c48297dfe28f98be4a9e9b225b748e71159de |