Sign inSign up
Syft

dhi.io/syft

Syft 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.52-alpine-dev, 1.52-alpine3.24-dev, 1.52.0-alpine-dev, 1.52.0-alpine3.24-dev

Index digest:

sha256:4b7d140c663ec13297359a84cd415fca54c313bd34be680ecad1198045d959a1

Manifest digest:

sha256:5e5394082c9c6e8d497a7ed0d090aecb3b624ffbb1b60758922c530bd47b5a75

Size

51.42 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:7fc6743f467d50870dcdc34e0154affaf02949384631fb6bf521606ba4f8014d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:99fafdb15262ddbb6fc0bf2a30c605447154f19fe3e193d9f27e8ca35b6c55ff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:ba25435906d5127af62738f8e175704710d772463fd4161a43ce734a319541d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:e9aa2584ecf2ca82c14a3ce5436888b330f19e3e06213796daf0570e67267ba0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:4c00b44503e18da10aa2b9c94e2ed52f37f73f1ec420c0594e9adfed194162d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:8adf9f791ea7f701d680247096c21f258033126462a66d55557fdd0c2e2f7357
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:f32ad39704e597a8375fa4ff4b295aadd57d620f1b002c341def9fa84587b24b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:9cdf21f5a9488a4eeeeeca6ea5e1d16080835e5238da7ddbfda8f683dde4d34b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:058a33f0879ab6f6efcf8d2ec7f9be2ea84dbad8dc99e4d7de9188d49f5621ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:6c7704803e4803f2e7f0b5609c34b2dfcad6d1304541bc49a80b33c861a2d8d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:9671a4d3ccb78521b278f2c23596d80eae474e72cf562504d624e8038421188f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:04dc10c140db349fecd1667325ec8a6c47c4ecf572a5812bb98e56c909747bd1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:2fbabf99e60587be1b52fde27cd0b9e74ccb5ff7dee4c6dce55cfe48bd9f9104
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:a51e65cc0413f8c775342345ceaeac750a1b79c7e07c3de813661ab2af66e5c3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:b6813161bcb167f41879a161c2f53d437a8c2cb83ea859e4b5951e9e91b61077