Sign inSign up
Syft

dhi.io/syft

Syft 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.52, 1.52-debian, 1.52-debian13, 1.52.0, 1.52.0-debian, 1.52.0-debian13

Index digest:

sha256:8a9b9d1effc15d58fb544068e0021028a362b630953ac765f2dd602aa91b75e4

Manifest digest:

sha256:676640d979d95f382d0feee77f5f12fb6b1ea53f244aa5ddc9a9f98988f5606b

Size

25.97 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:5168580022534864999e558cf661163ef0386f821a22fad2fae1c3b89294fc9d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:617b4fb6f7464e6d6fc30ebdfeab0d860ca24930f673048f66e781b883a09354
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:804380abb9bb6aab2540c7326217eec32d4e68934eeb66881a5dd08442454a18
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:cae44c4d00dff552d531c05fa3cef4bf887bbc73a33ec263ae41dda100903fd7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:653c95a1b810bd9db1109bf8237b65da97e6a4da02e3ac82a038e9759587037c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:0a30adec3a25a454add3e914cb54eac43eef2f78059f498fd8fa60ab7613720a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:9ece4ad712ad14f994ef758228bd05b5d71b9c1cf339537f1923bed26b270dc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:6bbe257573a930595f91964ca01c4b4e62ff2183522b07d4cfb9d8197145eb01
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:49f79a381d1eedc0595dba3d9dbe6a03f2a193b10bf5a29471df71ec5d87f417
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:96bb9a0fcf30106ed0a91ba8fac89b8917ca48fe5ef1365578b51ccc1fc9a119
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:112f892e811c9cede4b82e4364d09beacf7ab8da6acea0eb7c6a741f7f9e8ebc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:3e8084b3c7b8c7c4a1b20c6758d21737585270c5b3c368ca817c1d8c64a03da9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:7a5d48b4b2b67bc05597f332c5492d6d9af9da1469cd21225a4ab866980d8676
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:2a9cfabb845d079afc902894d7f48084277a903c5194a95d3667dbd01a03cfc5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:c41d0f1500c248c1d29a62f0e5a823afa7182a609274bbc42180753d865d9b67