dhi.io/build
2-alpine3.23, 2.24-alpine3.23, 2.24.0-alpine3.23
sha256:372be51b3d019734d0db25240fe95ce67b8d7297b7b0bd1e66df7307c1de6df7
Manifest digest:sha256:67f5eeca7946d70feb4bf3ec16a123b72c2cd1d39e5c51603f127787dceda7b5
Size
17.89 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-alpine3.232. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:2cf41c9d8f76e704b8ecdba8760d6e57a74d845b21c68ea89602cf2d940d50b6 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:0c54e1d78c2ea9096b1d08b126f6c3998fa4864fab6ceba5e53a35938ed63a08 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:f9a57b5283b1d6eedbb99e980032504760fa89334bdb00f0cfb755fbd1baf5bc |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:749266c9becb43dde8b0c61ecdf9757a14ef4244ce12304200c734b95e75eecc |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:89fd58a9961ba0bde8ff358305caf51f5dba583af5154db4b97b46760d0622bd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:c668847654a3a586ce980311b27c60bc493a7e17c143d96e6a0653a250d7ff93 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:65748c82d4db506578195f3db4a535dce5040128fce1d9b4f7a261d39bc66c25 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:a120af64f246d355f4c5fe98a89d50d1840d3b8da5f79d6a8a0d2e12e8439b84 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:d0d4a8a67575e69ffa5fb955d57a63d294886b988f574d8d1e874e907c771e0c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:1e0a8a92c267aef27d105fd00b70914f2f8c07791e734a8b8839e432c10034ac |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:6cd01e8e7e55493a5de987219305ce16f2fe903960dc75ef66dc5efda857541b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:c5c4fb57be73810cf9f8d4af4f0d3667285ea5b07fc1333bed30d679c04dad54 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:7c733d26254440a0bdc6242550d1d82e62c141049d9bdbb650411f7f2364fc31 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:e0242f87e47cb97de1d75db9c861af521bfd50dd63cc24f33aa7486567936231 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:f29c8d547e5cdd199479fa1b14829cb77d21bcbb6bf0cc5b580b899ee9331424 |