dhi.io/syft
1, 1-debian, 1-debian13, 1.52, 1.52-debian, 1.52-debian13, 1.52.0, 1.52.0-debian, 1.52.0-debian13
sha256:8a9b9d1effc15d58fb544068e0021028a362b630953ac765f2dd602aa91b75e4
Manifest digest:sha256:676640d979d95f382d0feee77f5f12fb6b1ea53f244aa5ddc9a9f98988f5606b
Size
25.97 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/syft:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/syft:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/syft@sha256:5168580022534864999e558cf661163ef0386f821a22fad2fae1c3b89294fc9d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/syft@sha256:617b4fb6f7464e6d6fc30ebdfeab0d860ca24930f673048f66e781b883a09354 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/syft@sha256:804380abb9bb6aab2540c7326217eec32d4e68934eeb66881a5dd08442454a18 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/syft@sha256:cae44c4d00dff552d531c05fa3cef4bf887bbc73a33ec263ae41dda100903fd7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/syft@sha256:653c95a1b810bd9db1109bf8237b65da97e6a4da02e3ac82a038e9759587037c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/syft@sha256:0a30adec3a25a454add3e914cb54eac43eef2f78059f498fd8fa60ab7613720a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/syft@sha256:9ece4ad712ad14f994ef758228bd05b5d71b9c1cf339537f1923bed26b270dc6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/syft@sha256:6bbe257573a930595f91964ca01c4b4e62ff2183522b07d4cfb9d8197145eb01 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/syft@sha256:49f79a381d1eedc0595dba3d9dbe6a03f2a193b10bf5a29471df71ec5d87f417 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/syft@sha256:96bb9a0fcf30106ed0a91ba8fac89b8917ca48fe5ef1365578b51ccc1fc9a119 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/syft@sha256:112f892e811c9cede4b82e4364d09beacf7ab8da6acea0eb7c6a741f7f9e8ebc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/syft@sha256:3e8084b3c7b8c7c4a1b20c6758d21737585270c5b3c368ca817c1d8c64a03da9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/syft@sha256:7a5d48b4b2b67bc05597f332c5492d6d9af9da1469cd21225a4ab866980d8676 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/syft@sha256:2a9cfabb845d079afc902894d7f48084277a903c5194a95d3667dbd01a03cfc5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/syft@sha256:c41d0f1500c248c1d29a62f0e5a823afa7182a609274bbc42180753d865d9b67 |