Sign inSign up
Static

dhi.io/static

Static (Alpine)

CIS
linux/amd64
alpine 3.23
Tags:

20260909-alpine3.23

Index digest:

sha256:1e3d8b147745322567a0e76069d30d2334f98689ca5b797b87df82dae0311396

Manifest digest:

sha256:19b8fe04e1dd14efb99db36c8176ccc368cb9841f1e077e353afb97f341d4345

Size

235.52 kB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/static:20260909-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/static:20260909-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/static@sha256:5ac6cd1ea4bc5cba82b1f649966adbc277aba25b570c0e15be535c4d62b13d50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/static@sha256:0e82dc38440036db18f05467241b28d37750acd4af0742de3d3fe207734cc517
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/static@sha256:6a6ad83c784dd1d14320efabdb09370fb5cbe533b370c30f0db4755ca9df8c4d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/static@sha256:e7c30e774a285ba259c0ad0592cc7c6f2ca046c344bdd4c54a73f7ea29aaa178
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/static@sha256:d7f029d12611d1cfeb7ea5ed1c3f62d68d0972f9ce557fc4c4c74cb50ab29acc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/static@sha256:b1339680cf2107c57a7af29d53f81c447ffcf94130a71ece1ef74475a6adeb4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/static@sha256:6f5b75c03a65376a0650968478fd8492013f2888968c1d4660b4993af34b454e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/static@sha256:678e99c51ae6a4fcfcb471d1b4d8132ffb7d61da239165809f2da5fa72281e97
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/static@sha256:791b9e9aa31cef990530c60824a3a1c7bb7ce889d80568b7f595dc80855aae68
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/static@sha256:8722138c60c004309611109506abbae66ba85a4eaee4f51aecf64c1aec90af78
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/static@sha256:de26e30797bb7b72d792eb3333c12c9fc0d63086aba26786d925329c271466d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/static@sha256:605548ed30adfdd5719a51c65073cb1527516fabd8c560977dd97c03db3a823e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/static@sha256:242df0e2dda9c14e298afe641703d1e845678c0e5c29b75b92b0dd0398213f2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/static@sha256:0a29934af3e4a65a5c2f407faad51d31778dc138125d398fe46139ca83727fe9