Sign inSign up
Static

dhi.io/static

Static (Alpine, with musl) (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

20260909-musl-alpine3.23-fips

Index digest:

sha256:a0915fde5db3e2a608361bc8d76e1a236158cf7aebbe81ea8df56ed5893c5b89

Manifest digest:

sha256:adc21326f3d8fba828c4ba612e517f2e070e88a40b5b67e9a7ef6321a960ef9f

Size

3.72 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/static:20260909-musl-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/static:20260909-musl-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/static@sha256:2dee7b5252a0af085273bd25b32a1c326a727c8bf6809c9c03e41699d2e522cb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/static@sha256:8b872fb85d1e6d35529def2a75b5150e199beb2cce08dca5080207d79f083c1c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/static@sha256:524ac9e049a1e767a57be76e8b0179554794bf9f8dab87a03852020c709def81
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/static@sha256:61c5bc3648d22ef797e58d4892c1f028c5a34ef0cc2a0b511099a9cc0f4e2a7a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/static@sha256:3a5eb4efa30e495c7d9d20e9317561e2e4331226b5db6820b9ba44cd150c4853
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/static@sha256:4a115166838bab8c08ad199b8e2087a78acb3979e54b70d848b8da61e0fa0ccb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/static@sha256:8f4f4481519988c52590331c37736d40a42ebba91ebc45e599b71a48c7035eca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/static@sha256:4df35f96625ab30518b30237f9dd52c67c4a79f1a48371b7d3a9c79dd51e9b28
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/static@sha256:487e73aaa3775bc3f6218a7647cceaf9be4ef91ac34842815f3f2a5aa818c894
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/static@sha256:5b51d831e474b220a6364b4e79e403943d18fb20878c939c5c32cda63987348a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/static@sha256:3cccea5b65804f73c89e1a76da1b4dfd4e30d9084450244f778646dba6290603
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/static@sha256:e8e22bde6c762dde1b4df95202068e49711afe003037118c3ec86f2789fbbcff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/static@sha256:3ab84456037ff0a667c34aa3b9786cc75a5efb837cae6deb794f122f51a1a804
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/static@sha256:70927472002e591e104c29034029a5ef8430c29d268d4c10dfe52a09d4a7dffc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/static@sha256:a195735bbd7554412b754eeef29d2aa26b842ba431c2f9be0a0d0019421f83bd