Sign inSign up
Syft

dhi.io/syft

Syft 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.51-debian-dev, 1.51-debian13-dev, 1.51-dev, 1.51.1-debian-dev, 1.51.1-debian13-dev, 1.51.1-dev

Index digest:

sha256:2a11cf66039382b3b773821ab71bf268c90473f2e2573c74dccea5e5fc2bb46e

Manifest digest:

sha256:ef58095b143e78a174f528dabc61f24cefad4722a20e6a82ca3d41fb77497d37

Size

70.69 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:ca7d0d79d90bc9f3f8bf82d49bfaa0a14800a08077f4797a75f072d4e2db5901
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:caf0705eb813c75f7caf14fb3a5fb66c7b0af11917b9b85cf08848a21227e2a2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:67627992272ba2fb74df2db82958db5943e7fc79d05fda1ab59c0805ffeb5c73
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:698c14f430ef67e4b4263887b94e421072014a91e1717da86b3b26f5a617d6b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:a5e80657a6194455d86d16369b682909851963a7bbbca88e6a92fb6330e3bd30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:68bc7fc3984c0ba383d8be0e21fd4d5ab689d1cfdff33cf48786419ed8609d34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:b3bd1fb28015c2163e8112a649c1f09b683cbc4711999d373950a0170e8be7e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:e5cf2e1716da7ff436e096cf82b5d4576d50fb5d5c8214b5462b781741a61371
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:68c2216ffacdea25c733e9ecc2598569b9a254abb1b87d90fd1ea2ad92dc9a5b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:07e08f00e9d85705d31a0db0629bcc5e5129e4f525033d8c1269a93da3aa9583
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:4fb6969fea5fdc721a73769ef89aa378a8cf4bbe94a0ae3260d3d19e24761533
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:ba9d0ac1a67df210cbac2539bc601af450b4c5c939707d3c1daee37cbb5d7afc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:c47eec8b11fb55837c86bfcc197387cf5b102c823b71315fdcc91b784f462d2d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:d65e044f14d204a6879362b8bd3a5bed7ef25684d22a9597b2344d77224ceefc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:d7d902fe809b34ca57b06f538c1b6578e3a0c3ee998bc3eb002440b99a05e0b8