Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.1307-alpine-dev, 1.1307-alpine3.24-dev, 1.1307.4-alpine-dev, 1.1307.4-alpine3.24-dev

Index digest:

sha256:141574681f00dafa5a2b8e547efb6ad8cde2905e989e2a1728825efba9d7e936

Manifest digest:

sha256:0b87f4dcd8efab7fe636bb653dd9be8070fe924926f778da5a2e970bf11926fd

Size

74.11 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:fdf3c150abfb059247efc83a2c1d11146e4f0cea4b7b170138948e58f0772041
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:080318c3ff5fa6df844b1293ae4a2c7736f9f0b5e84d4c414c00e01846c71f7e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:5fc5169a38222f5bffdcf8ded87dd057c4229ca5278cb7e78ed38674c29322f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:e4e5bc2b4f156ebe84bee27e9d2b7075699644ddd51a6cc6c3ee4aabb7cfc60e
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:a355ea739b28977d04cb03a4f03facc64dde061e19a1582978aeb3c8797ab172
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:b9a58509a9677dd9d2d63b825194a65c8cb23b7fd12484ed26df781870f57e07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:2eeacc24971c0f431a31de2ed14ead5193d7f6dd5493eaa2f378e0e449e1142f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:85199e7b52b37b0eb1132ac9693bc5487ff283c2944038f43dbb43a560a0804e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:747e63b8716e695cf1cb0a4fdfdf947441d8180e12511be7d75beb71f27c2fa5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:6c9e812204444fc28e98516ec5f2425edbcfa5765900cd2c368c914560854d22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:9845971049a2d07d0df4dadba90d4f0655f971ef5e64a4cde71b2c1a1bbc6e4a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:75e1982ca6436651bfade90c159f2289e34e4169b3cdbda57342ea7836b3aa04
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:6266cd97dd7c25ce5c882154e481351ab91a6c6d26b291419990a9c8e88ce685
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:6235af8f21c24c91ba711b416237484190059087775ed5cf95e60d906f496588
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:a640339177e6450cbf37c31850d80096b2e368e74f96b5d34f4b9a24ea93503a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:621fd8424097717998c2ca4503f5842a615eca9ae09ad44a9898a2bf0f6a7feb