Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.1307, 1.1307-debian, 1.1307-debian13, 1.1307.2, 1.1307.2-debian, 1.1307.2-debian13

Index digest:

sha256:e54a2bcef94d3a431699c7f1c15304053a303bf62c62abd7f746194066521b4d

Manifest digest:

sha256:c5104c1abe6bba5f7427d948845c3b0e044e3c1cdf2a7b05ed1c5fa5c120b6c5

Size

73.82 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:a5519d3832d8d5df1790348e20f96327cc5ad2eb6ff9b9f65e83010f3e1f8b7e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:1cdb64b61cb044da7560660306a35a085a77f3866253b28cc9c722a2a2bdb2ff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:c791e67481295c11a330b4248c3b9f7cb8bc1c86656508052685a8fcfacd02e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:c86602a3672d1bd7eab696a5d6320e4249c6573ee5cf308afba969f524953473
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:c6551d74ee64c2eac475588d0fb22dd4d67313e3f3ea387496148a798e4e6444
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:531df073b35ba7f378dad1132edf1148b11ceec3a98d1b12090fe99d5223d228
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:c95f2995f22a71ab0bdefdccf9e198ca8e7958dcb0f62e50a4b436d0bd43fbbd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:019c2dff142f8f4be208d1cc9b86f617b6257dcd5d5045d54e626c5fdbce3e46
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:6cb5a5a0580a05285208a2932c249fd991066e740dfdc3180cfca13abcfa678a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:4611d0547d0dcd327ca7d4b222511edb41a8f6c92947dca3e160868e2ee1288e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:3c76162c0d30d270d6b02f6340e9aca664677f983c7accf705721098b439b05a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:d9a11caf26be00d4770759ac0c88719e5b84036b1afa53de25b662599677f7c3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:24cb70deb7b70d74e2f218446558cb91bae569d62e70b8ee384e63c6f8494fd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:100d44c049745198c25f10becdfab4bcc63a14cbeb7c86351fa3876a22f9bb36
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:cf5ac320cb3878dc7ca9ba6cf6ec57480b99ae42bfcfc55cd54f78c06860026e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:108657d190f53ae532d95c820cc7347db8475f5c8c030cee46f15f4f6c236bf9