Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.3-alpine-fips-dev, 1.3-alpine3.24-fips-dev, 1.3.4-alpine-fips-dev, 1.3.4-alpine3.24-fips-dev

Index digest:

sha256:ff1c8be0e5a5238ce3206ff3db81163702eb3078d8b754ddbf22a213176d0c5e

Manifest digest:

sha256:87f46ba438759d9fa457b3bb61e829da59fbde121779485e887b4225e746fa86

Size

12.83 MB

Last pushed

4 days ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:2c082b04608a02d4fa30173cdd9ca5caddcaedf5037b7e13360724a216b815c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:6b88f9f2287018e970aea1f4c4de9d27ae5ef7b1529db42d85e2a5fbc18b0860
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oras@sha256:7c1fd2be3340c0a34e9e9c758ea4f77bf767ae2adf66ba2e3cdf880e2d6659a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:75d850517b0367eeacac420ad70fca81fc41f14aa74bb66712ed7403007233d4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oras@sha256:38b0fa789e4586f726b9a3d9a65959fb83b521fa409256777dea0d551e3ab7e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:270456b485006c7fcd43777a85b8d449487056c4918a102ac0133de20c54b794
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:8b77c9609721148f27bb5cf4b023757e254111a26631e1cc67f8606953b00d88
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:20030310f374ac65b13d704fc72aef8c7180a5bcbf97878623f3daabed0bd049
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:ba5d671bdba448faa4e0f3400e8c81603764c952d39b1c3b744cd9b01696d904
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:7d6d7e4d5268bcb00a5c6d2e8718f7d4b2207e88e518530b5e1da5dcb97c86e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:f0c0fdd9638672c2970ddc1a1ed34a61d21171cf6f50384798186c2f0a37eddb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:5dc1b312f534cbca8f0fed0df52f41a7f8f741c54878a582a8ae5e69d63036b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:5d1fddef2229f5e13a591986f55a3a589b4b9cd544621afdf290eca250f73866
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:bba8592f974cc1840fcc23f42b2e3933818578509c3d03cefc26ff662eec1216
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:0b3495f733cd7c7c9f41170ed71793be77f672039aebd10de5cd2eb634a213ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:9929639b735ad9f8ce4913ebf86be33fcad9ab6ecd4a6866cc99dd497ed90b98
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:0785419197c7ece558dbb2a0073c48297dfe28f98be4a9e9b225b748e71159de