Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.1307-alpine, 1.1307-alpine3.24, 1.1307.2-alpine, 1.1307.2-alpine3.24

Index digest:

sha256:a2e774041129f4c3e92b61c39e6391959777bad16c4c8449bc1cfff0e0118ed7

Manifest digest:

sha256:1eae571ecde2bcc47ecfd55c7143352eebd840a687621aa424610be144d1d656

Size

68.96 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:c0e00a21cc2c902b250c451df925e971fa1c60c5ed868e95f0ebfe7b1bfae43a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:32eb2cfcfb20d7e4968c46b6ca8bb5b68341905f451d4bb3757da2b310a2453d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:567cb7cf252212b8ae31838f9f1b2c29b579c782822073cbd6bc421355056aa3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:9a83522fb7558a549a1161fe8a29a9a18dc3bade6731f8105e4fca130dc5b7b0
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:10579c64a6ff16c25310a11fcd9f2d902d89ffd6196ab4d37cbd1b11d19c621d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:924599f2fd68a1ee78c93babcc97b9be40ed8f52b5fc0a0db6ef27a44e6650f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:a2c43b10e1cb72c16dc4a892273fc342c5051d285026a4c121b94b5f066c3764
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:19931061b66579e0e59379ab5f9abe47d39bffac7b2a63c510dafe9928485e7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:745201646fac5730cae8e60412b609037300bef39fb973462add7eb231286abf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:7f45191646e13ab44ca728cb0a10bb670f1c1f77ca11ef97fcbf19cb66363306
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:cd61a367e0a14680429a43a977b328ae13d16fe84a1f529bfdcb2ece3e4f002b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:1dc254154dc626f59d69e568204a72c36463e38891cee0ba7f55d3a2df63478d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:61da8106a6d9b7924d0f602432a66042ccfa229e63f2b74489076f3968ddab4f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:e5469995df1e9d20f122160466f569678f76c971fd219b7aaf2e1f743ab5cee9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:abe2a0f695d9a8fa72816cf9f254f70bcbce48fb8b45f094775c22801f92efea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:eb8ce0380a73872c78da9da34a17ca81ae3fbc3ad52f92dc0512ccd5f1da59e6