Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.23 Base (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.23-alpine3.23-dev, 3.23-dev

Index digest:

sha256:deabb21a9d62c3f54a72a15ba19f779b73cb55e4fdd1b476548d09dd3d488a87

Manifest digest:

sha256:997072d8596feffc539d6c24e10e16a63f602ac85993f15b9ffebfff47acdae4

Size

3.40 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.23-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.23-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:942c4cb3f399c5a9440b451f98a99d9672b40bcfd61c54485bd86053ae77081e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:8e3416bcc38d531e444cac8c7a24ad7ae6a3ab3a74e94524d340afae9801f0d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:aa936b86a87aa587759b0353693bc7f11e6e71c7a68df622d02d9fa19435037e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:5e7568a561c479af08d12de9315dad270bf134e2a0dde1ca7e5153d021bb6c1f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:f6058f8c74a8cf5ccb6be48d7c56f4475351ed97584fa007f8b6ddd5768eed91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:87bb188fb69b47a5ac6e539d8cce4d7d8891ad46258cd343d55d4468ca14f917
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:c22271b946e13a427a75ca6d7a91caf32ce166bc0ff3e43c8ca624fbd3be94d0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:9d607ccb6e3e848b0c54d61def019ea0814e9953e080899b8afbe7c8b4e4e5cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:83b6c79036ceddc91eae63e955579feae99b19fa69bab1a1a886b0d181d9679a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:71046b9fed4d0dc7e88a2d359147c1170b9e2491e4a48370ae4a100cb0b346ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:32ea33b6af4e1313346b3fb7abe97e860036c35c968e901bef6cf84decc63290
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:8c643afb4ba9913c6ab15bd43389a63cc9dcbdf4ff6e56091e0741168647445e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:8c38e2e82659e20d70a097f89d0765106a405def31e59c512bdbf357c4459a60
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:675b329aa05110824f367e486f513738279e170bb9b456afc695b05866ae0c61