Sign inSign up
DHI Build

dhi.io/build

DHI Build 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine3.23, 2.24-alpine3.23, 2.24.0-alpine3.23

Index digest:

sha256:372be51b3d019734d0db25240fe95ce67b8d7297b7b0bd1e66df7307c1de6df7

Manifest digest:

sha256:67f5eeca7946d70feb4bf3ec16a123b72c2cd1d39e5c51603f127787dceda7b5

Size

17.89 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/build:2-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/build:2-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/build@sha256:2cf41c9d8f76e704b8ecdba8760d6e57a74d845b21c68ea89602cf2d940d50b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/build@sha256:0c54e1d78c2ea9096b1d08b126f6c3998fa4864fab6ceba5e53a35938ed63a08
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/build@sha256:f9a57b5283b1d6eedbb99e980032504760fa89334bdb00f0cfb755fbd1baf5bc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/build@sha256:749266c9becb43dde8b0c61ecdf9757a14ef4244ce12304200c734b95e75eecc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/build@sha256:89fd58a9961ba0bde8ff358305caf51f5dba583af5154db4b97b46760d0622bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/build@sha256:c668847654a3a586ce980311b27c60bc493a7e17c143d96e6a0653a250d7ff93
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/build@sha256:65748c82d4db506578195f3db4a535dce5040128fce1d9b4f7a261d39bc66c25
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/build@sha256:a120af64f246d355f4c5fe98a89d50d1840d3b8da5f79d6a8a0d2e12e8439b84
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/build@sha256:d0d4a8a67575e69ffa5fb955d57a63d294886b988f574d8d1e874e907c771e0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/build@sha256:1e0a8a92c267aef27d105fd00b70914f2f8c07791e734a8b8839e432c10034ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/build@sha256:6cd01e8e7e55493a5de987219305ce16f2fe903960dc75ef66dc5efda857541b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/build@sha256:c5c4fb57be73810cf9f8d4af4f0d3667285ea5b07fc1333bed30d679c04dad54
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/build@sha256:7c733d26254440a0bdc6242550d1d82e62c141049d9bdbb650411f7f2364fc31
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/build@sha256:e0242f87e47cb97de1d75db9c861af521bfd50dd63cc24f33aa7486567936231
SPDX SBOMhttps://spdx.dev/Documentdhi.io/build@sha256:f29c8d547e5cdd199479fa1b14829cb77d21bcbb6bf0cc5b580b899ee9331424