dhi.io/notation
1-alpine3.23, 1.3-alpine3.23, 1.3.2-alpine3.23
sha256:c2f0069b0777ed4f400f4a043f979c3670dfab34fa1e23e9336bbe187e4948e4
Manifest digest:sha256:c4f17996cb802e999dd333a18cba02c6399ecc3e16e2a7fbfeaddef92f54fd45
Size
3.77 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-alpine3.232. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:446eca9816de9dd33519a4a5d727e6123401ed2178768a7c484a68ffea23fc00 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:fb17a06b1205874e7038d2d88abfddf636cab4427952dca06e9a70393a22a8a7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:2b0a0ea78661ce59d3aea85f9e47d507455c1985d5c848a7d19008d3ce46903c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:033cebf87f2ea574962364e519d5d8a2043918dbf3d4458827cb62c68dfd869a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:06b05798c9c21822c16d1dd2fe3374cbf4d8f4ca38547c5f1df38c3932b2a7ec |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:4491b7f781752a96e66cfb1276dfd932a696d2e903a7ac400350538f1681e1ba |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:e374baa8e38a331b7a3c1a03fa0cfda3d2aee56f87118327530e89495af2013a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:b2f67b2809b4c4ffe55779bcd998b4628e759524a2da1e4164192619b1a15958 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:5ae15962b5bfaab61eaa9b9ad41c4229d460b19990d460e9f2bfe96e3450ceee |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:59c88df31aace8153ad5c5495988ede736241b325d9c86dd01092d728271b104 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:8c2146d6b8b320e6eb399de840b7e2dc3aff49d88fff9437c5238cde14fda60e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:5708b5b7c1159d469bf21d9d317a420ce13d44ba804ad764ae39fe308c0f12e5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:64216bffaacc3034b2e8650a5f9b4ed9f5fb7f7ed027ca1c3f77bf0bd8e5e80f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:d394ebc07feff28379523ff100a74a0ddf34d93cc28d679454d70efdc64e1c98 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:3f21042dc2b0d14e68811c324d56009acbe4409c129ebd3664da9844f5f24d5d |