dhi.io/snyk
1, 1-debian, 1-debian13, 1.1307, 1.1307-debian, 1.1307-debian13, 1.1307.3, 1.1307.3-debian, 1.1307.3-debian13
sha256:f1a4741e640b7e89ab4689dcacfc8be8f7ba0bfcc03e32ff502a2a3c0afaf263
Manifest digest:sha256:2e8f9f3eba074df4e30d41f9c48363ec58bb3fb78b2457f724e7e2d812913804
Size
73.91 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/snyk:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/snyk:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/snyk@sha256:e6a7f5fae3ee055c51807d1a71b1d5a547772bd41910143b9064c155d6badd3f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/snyk@sha256:9b38b5f3f46175c8eb64c669454fceb5a4478d80bbefbe29ea0b1db4c3a510e8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/snyk@sha256:2dbcf75fa660f3de503aaaaa3571691248030e799a8e096599a8b7557ed13e09 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/snyk@sha256:a9d1c3356b4781d5d59f1c7f7242695b7b06f312ce73005fa7145810a451f268 |
| MCP server.json v1 | https://modelcontextprotocol.io/server.json/v1 | dhi.io/snyk@sha256:8f7c303a28e05fdfc351260a31fabae24a77382661fa3294a13ea4b59d068ac4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/snyk@sha256:de562ba324c449cdbdb98f2a7ce3683f809ff3b2965cc3c5961a68ff1453b1f6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/snyk@sha256:33e64c0f22f27ae7b8df7916ea81f41a98b0288f299e4fb77b73632e450e5fcd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/snyk@sha256:2d4eb251be4599e71a38f9f918bc9971febadb79047750c527b78980bc322539 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/snyk@sha256:db6649240be66ebd1dd398d2a5beff4c634b4a91886d7e483eff7672b382a5d3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/snyk@sha256:6c99e0ad1dfd6fab682e922c61165a5295c2372e838b420e5af01112dc1dd044 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/snyk@sha256:73156343fbeb23018563d01c3ed72df4731743c1637768ed43dbe6453e796c5f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/snyk@sha256:50602b70b1b3a82a11ac3fe270254b0ac65dfe1ffce489b63a0f9eaa6312ceaf |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/snyk@sha256:126ec246ed972081eef8d38e8153c178f64e1e21d94d293687df7b6cdc290289 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/snyk@sha256:b8b049ea74204446fa793cafdd2848b3529cae6d8ac84fe05d832596524c4aef |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/snyk@sha256:d43ab61afdc18d718aef07378d6ade9905d8a7321611ceb984377ebc831e4f85 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/snyk@sha256:f7654b136ad0f3d40714555ce59eded6481d46d765957efc7bec81f595c468ad |