Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.1308-debian-dev, 1.1308-debian13-dev, 1.1308-dev, 1.1308.0-debian-dev, 1.1308.0-debian13-dev, 1.1308.0-dev

Index digest:

sha256:b14d8f9b43c716c66ea8976e9010a79624a15e859c0ae021b068b42e7c03b7f1

Manifest digest:

sha256:de223e5e6bbee44fe1266d02393469004fd0dc036befc6b6dda0db7a4bd59774

Size

87.40 MB

Last pushed

15 hours ago

Vulnerabilities

2
9
1
2
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:e5fdf336f2d7a90db7ce290849b4cb95864e90970cdddf14f0cafc37f25e7119
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:ccc924327d1f54914a44d2bf0dd98be5b9c89d59a903616fb922464d90ed5a45
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:8f607e8b472de5aad84cfaec0cd112a0e1ebe229dcdaaa72c6332a43e028a5d9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:0fd563c604c5577cd0dc7bae8f4679f6268747cfc4cc3bd0742ac56a90a8d786
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:d1ffbd3d4c72d03e6f3bde6ebe745953e11ecef718476ee20dee5d36e5c74755
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:0bc03add64714b61b5c4d7e6a785b9087c7660aa5c77c7e8ff1cd8d4da4a29b5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:728d9d121d4c5c9ffe1877954ff4aab662743e4ec71b40d19f03506a8134542f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:4dae20ddbbff149d14e80fe4619c43d675c9cb09c4a6cc7405020e0a610f6658
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:7ae21a083b198f103cfbd7a0870ba2cc39f482894a0e84fa1a5691e6f7c9f62d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:9f6f02faaf3cd4bebce571c96d14781c4ebed92a8880d2e1dc5fda1402f7f71d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:ce820192685feec8e7f1af40f279884598da235a31d93a51c7af6eec622000f1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:ddb3540ca606c24d541161f0d59d9d093d797e182c670df0fe5353ef56b3bc35
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:242fa577a82e556f9d839a028c8512fedcd0b6f1ee18897f02207ee62aae8d5d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:cfc4f4b1835088f8eb1aced554eaa5d37a73b4cd5ca3265d3facd2b95507d9dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:e9b5778d4e27ab2e0b0374f266d5d3df8186a44888ee7ef1aa0445bb17c0a7fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:c995f01cc1a7a07e639ad7d3a865609f81a5196bc027f1c26895b5298b02e251