Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.23 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.23-alpine3.23-fips-dev, 3.23-fips-dev

Index digest:

sha256:b66ea2eb0dc0ee968d865024ceed6222fa46f119f82cc46a78fa3d6135962479

Manifest digest:

sha256:a233091bccad8efb7c9d6c525075b04f6c1b64a9d714b643c7bf8697a881c9bf

Size

4.23 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.23-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.23-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:40305799956e01a78a927ef21231314c40f38fc9f3d62c548377f11987047be6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:18414a13ef1241839f49b0449395cc8e2c55c24759e8da5724bc1f24177de3b1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alpine-base@sha256:54307178f7118ff868af440f026842b857d890489b0b0f6b285620b8b240fa0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:7ab372cda52ea68562588b80d107a4ab03f0d86d4a77984885a1ddc426f40ac0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alpine-base@sha256:8dde3f1cf8b56b243a9e58c13a4268c498658ddac7745b85cacf260f2b80d5fb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:1e204eb7510364ea2da0a2ac57cb95f7f21b9664dea3691f7dca741dc61249b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:aa9b4edccde3fb9547a09bbfde0dd4a88a5f2c032fe65622129686a7b6bfc435
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:eed3d12c289014d0e3283198ebf01e40bedb70b04f07b95d90b2b75eca680845
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:746054c98fb938895381245d28a13b09e75c6b3783622ee40868867587f4a31c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:cbae2d47af4e99b12910de410fe0e24b9169204b043cf07c5717340609d6f592
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:df8ee11a3c07a38c177f4a989b2d0b0dab25366fe36dc121c569139d8afc14d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:955930abeda9a305ce21d9a86b612231c73dd934bd800743307e7c2e560e97d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:ec55042c34e101d5b72c3b6111ec924a2ca53882ee939f251da48ee57e0b7015
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:204d219c6cabc0e0c796b92dc66887cf5244b66d7f4c5588982e9e9e3958d5ce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:46dfdd3e4e15251bd5bf540e7471bd053c78129338c1a7ad3648a20fe2a0d8c1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:26b6fe791391e612aa7307d8ed8ba62b41c1a02d911e6202970d3d361c6e1a16