Sign inSign up
Static

dhi.io/static

Static (Alpine, with musl)

CIS
linux/amd64
alpine 3.24
Tags:

20260909-musl-alpine, 20260909-musl-alpine3.24

Index digest:

sha256:b7ad088799b799eccc07afe538fb69815d73e6299f0813df81438bea0e86abb7

Manifest digest:

sha256:e15da33898a27ac357460eb2a100428daac9ab9fd7933d6f3bed3cea12c43f25

Size

727.04 kB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/static:20260909-musl-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/static:20260909-musl-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/static@sha256:24f57e40ded265f380a2dad867849e269e34853fad55ab2a09b037d3a0792f53
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/static@sha256:d8d43dee5df8e64372ffc10d7bd055ecfc5c9fb115a97f2e2205980ba29f068a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/static@sha256:c378167605a24cf4848e838a047b698c69d6f6ca841a5e969e0def826a86b14b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/static@sha256:bd36e08274f90c2c795fcb7c8c34b6c648032361419ff0bd6c361a6cac2ea9c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/static@sha256:a26df8733417450efb73bac4f0598ac95d1d5630ddb59f53cb9e798ce1483631
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/static@sha256:452394e8dda52b94da4bc30b186c74f8b4d693a7523bebec14bd9959addb5886
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/static@sha256:dab529694b32f2b7f949e26f7c502d5777cbc81ae3d5de5cd12651a23a01501e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/static@sha256:1ed473b6a7165cac3ef36bab76a952aef20f4e6932fe8f88cc0e0f79445fa263
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/static@sha256:3deea547c6caf9b42e0fc58f05a7a2d24ebcde01d9ce5a6d1c1d569559275276
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/static@sha256:bb90e71511d3441264cba7e7e95c516fe0d8099c7f300bd188c277033bacd3e0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/static@sha256:8721ddccb4e09eb77425c220128210f629a21f030bed6b5b5e22afd4c1d2d46a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/static@sha256:a8d42242fb17f46f103a77e57404891c58cd5efcd29cf1ceaed766edf0056cf9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/static@sha256:bd4cc4b55719be9f9617f83ba8c910016a9d4243302972994151baad9fc3a53c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/static@sha256:2179ba8da212cf06631626ac26fbf708f96ec0ac3d7ac11f7ea3b74bc0890a96