Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.1308, 1.1308-debian, 1.1308-debian13, 1.1308.0, 1.1308.0-debian, 1.1308.0-debian13

Index digest:

sha256:edf54d6c9072f5f13f076a172e39634d80a00da77d20ab4d0f039cf5cf60552a

Manifest digest:

sha256:f9d13cf77c865823ce9f4e2fdf085ec3bccb0dd4f169da2e38a0f7ea9fddf30b

Size

72.50 MB

Last pushed

2 days ago

Vulnerabilities

2
9
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:fa0bdef862e2de6b2ce40d76880ed13570c9aa5b22f6c7a2c44c50aa59123857
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:b8b43b2e5e21ea562d966c3902f30de7df6a206c761a9a7407749379f5818fea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:1daef112cea14a4c4759c3b1a8984bb52c78aab279e9c3ec1e7b55ddb50b59f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:72adbdd41987b294a79b50be732e8b02878d6ab44ac06e21d86391e29d63887f
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:70250883d630cb6094b6abf788eb5f94ac7b2212685fc54bf5b7d449787bf3fb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:052b9fa9e2659f8fa56c4e74fb6104f1d6c85f6e6bb19a7553d8936dff04a9e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:4d90fa258ee500ea79cc597a833fcb1d51dba1aeb4335b160c6976586dbee852
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:0b5d8d3763b8ff555799e2ecb630c399da94760d0fbad22ab80d8e4863b24b4d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:d53db852e180092ed5e97b3df9a2172939f986815cac7f09cc453bcdb3f42eb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:cef691ff722198b58930716461fbb2741334c572e29634fbc1591010452522cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:9007a1a93c8a513d9447f656f2d890f294c564fb6e2d48680e9168dd5d1311e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:7c0e307924b8dcd05d9e6d76a5355cd3a45877f5353685e6619d5a9dca07da9b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:c4c5c7a944ecc406f12fe85505d07ca502da8739f7611cd43fa789e233a103b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:49ef972a7fc19fd843aef5a8c9c4b5b5b998965c2377de40a3727596b557f98c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:242d7bb77624d73bcfe38f32f12fcc7e45b8b7751c99c4e279a83254154e1275
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:b45d46c27928e607b7d33d322f20793db7407ff045926fab0c197c602b13b2b7