Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.1307, 1.1307-debian, 1.1307-debian13, 1.1307.3, 1.1307.3-debian, 1.1307.3-debian13

Index digest:

sha256:f1a4741e640b7e89ab4689dcacfc8be8f7ba0bfcc03e32ff502a2a3c0afaf263

Manifest digest:

sha256:2e8f9f3eba074df4e30d41f9c48363ec58bb3fb78b2457f724e7e2d812913804

Size

73.91 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:e6a7f5fae3ee055c51807d1a71b1d5a547772bd41910143b9064c155d6badd3f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:9b38b5f3f46175c8eb64c669454fceb5a4478d80bbefbe29ea0b1db4c3a510e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:2dbcf75fa660f3de503aaaaa3571691248030e799a8e096599a8b7557ed13e09
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:a9d1c3356b4781d5d59f1c7f7242695b7b06f312ce73005fa7145810a451f268
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:8f7c303a28e05fdfc351260a31fabae24a77382661fa3294a13ea4b59d068ac4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:de562ba324c449cdbdb98f2a7ce3683f809ff3b2965cc3c5961a68ff1453b1f6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:33e64c0f22f27ae7b8df7916ea81f41a98b0288f299e4fb77b73632e450e5fcd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:2d4eb251be4599e71a38f9f918bc9971febadb79047750c527b78980bc322539
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:db6649240be66ebd1dd398d2a5beff4c634b4a91886d7e483eff7672b382a5d3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:6c99e0ad1dfd6fab682e922c61165a5295c2372e838b420e5af01112dc1dd044
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:73156343fbeb23018563d01c3ed72df4731743c1637768ed43dbe6453e796c5f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:50602b70b1b3a82a11ac3fe270254b0ac65dfe1ffce489b63a0f9eaa6312ceaf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:126ec246ed972081eef8d38e8153c178f64e1e21d94d293687df7b6cdc290289
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:b8b049ea74204446fa793cafdd2848b3529cae6d8ac84fe05d832596524c4aef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:d43ab61afdc18d718aef07378d6ade9905d8a7321611ceb984377ebc831e4f85
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:f7654b136ad0f3d40714555ce59eded6481d46d765957efc7bec81f595c468ad