Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.52-alpine-fips, 1.52-alpine3.24-fips, 1.52.0-alpine-fips, 1.52.0-alpine3.24-fips

Index digest:

sha256:7fe899d90acfc773a45525a90fb34dba3e117cfb8329183d7105954e1fec5d92

Manifest digest:

sha256:963148a26fe648099bfc7dc354dee5aed1c1ef38627ca76a6f47cadc0000bee4

Size

29.10 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:e47fb2a772e3177688959d9881f8a3b45fc964ca293a6ee1d2d193dee7637df1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:dddf888b0a1372e511762156ebad7af0a99ddcee8fbf3c2a9a7efd85f3bade08
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:ef585e44e5cc9f3776be4a838056399e921d10a92312bea622f38c430c6b7036
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:c6dab2b2be5ecc6ae7d8836e7d3517fa12b6551d6dc7b0c795f670b697fa18b1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:0286d3ad55600a38a269e7fa105e2e2b4d4c5a47df361a978e96fc904fdc50e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:410fc7cbc700e4daada1a15d4dd0a9aafff8577701a4bdcdecb99229898b21ee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:a96ecc5bd8eaf6f3252d57883a4202442239a590e2a4a6bbb7fe81a8aca8b19c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:dd6acfde6f06dec068902c6e2909b3d2950cf4b6b3b5ef70e4d1a931ca3468fd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:8ff272e51803eb52c733d3a337047b1e5d54b3f68517d718e2f3d2087e3ec994
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:ffe5c582d07680bfc6ea0752b041d99d539cbc2e1725c27554e28e2cb974e407
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:70984800422b5cfc804169126a2e0d5cf41876edb7f708c58760ab0ec43d73ca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:9bb2d99d62254802739768b55f1c12a6e58f617293f172a72b9198e5d0c765d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:4832cbe7f673beb6dee92daefc199178c35a463944221b633162c916d4bf6e94
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:5b1f2d52ab9410dd34d43a28cc614fc629a87803eef65f1bf55f1432a31cf841
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:65f7fd85c71153adacfd5b4715539ce1e0346460fae83f4f21fe1ceb9e7a9505
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:c0a78216fe02f614da87e767b8a732411a8f7401d6e248cb6cf9aa4e252693fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:6516b5160338c1d26d0917941c1eb7310e856f0c21cfa92de360a09d03c7b9fe