Sign inSign up
Syft

dhi.io/syft

Syft 1.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23, 1.51-alpine3.23, 1.51.1-alpine3.23

Index digest:

sha256:97ac148c10e0b61e0ebe1c6c0b0a839d4285a4e32cd1df076bbc8b00075a0280

Manifest digest:

sha256:ea245eff96fab66ec9ef8e6e9bdc8f571a2a7af0608fe230c75da79ee1a40f58

Size

25.61 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:991d53ec782c71b8e1846447783a51e75125e2c3617289d01be3095ec9962009
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:15a55852398d5eb4f4fafd4a85aa162c12ce864f19d1a8f43aa498d3038e88fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:47c33ab2fcf6b971afca2fe9f03f64f3babe85f6716ee2d587e3cbfae30c8070
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:da7eef7d31f44413c34ecad8d6409ee927624dae652d1aa404ab320e640b42df
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:2d0ab2bcd323a4912497a2586c557a6c971002f517ec1a5f60dd3c77e06b4ad3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:67fd02a558348d1f73f42f05ef73f20222b680cf25d31a8e06e472e50ac5af24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:525db6638a1fa5da2e3090f3f676775fb21deb9a2f00fd264e684687a0314089
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:c8d24a08b6c58845aad468c3783a75e38ae4ea266871b504518be9feeb830902
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:c251ce48e6680813e15ad4e7e7e6a55ff761017b69299c0deee3c036c30642fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:68578f3db395c79e945a59967b915dc0dd68997935e4dd58b20947e8c5daa21c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:e625c7cf334fa7d23f41972c82a1f764c043dc5b30e8e58382caa47aeff1ca6a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:e4b3ed54b997fc9d7a8ecf2176f584765e8a2ffcc23cae31ac3da31c78621440
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:906aba68129c976e77cfbd4bd007e85cf598ca86f9281d96796ae5835e8d0ae9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:f24309581fbe8364a81587f4f5a57be042a9b976359d443337dba65910dda7f0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:d55e9e1ec76d2b007fc1e8694b24ff2d224f11743e0ccfa172710c2afe4b5c20