Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.23 Base (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3.23-alpine3.23-dev, 3.23-dev

Index digest:

sha256:570ed79e16f93cc465526041b57cf448215018cfd633a6b1e0c00a5c9af09204

Manifest digest:

sha256:9b8af4e36fec70e02ea73d0c8a118cf9ecc0058bda9a4791dcacb173122d101a

Size

3.39 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.23-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.23-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:e8bd60dc656122997923c1cbe5a70eb4bea42065c12eb71d18a462dcbf3a65ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:ef35c1990d2fb43a03af11478559385ee3211d31db901e3a744dfa93257d8069
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:84e01ce46785a63e15f3c2a9227351e3b7abf049bd1b5897e9c8fcadb230dfb0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:a87d27db534a9baeb6f2cfd80298295b8e7498a13b998371554a99f684dca210
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:29f05963afb8b59981925c994612ff4234a0bcd2446148e4ba03b77627e4cc82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:f999160c98bdba8ff8c8bf3276d15bc06fda449a306d2f28aa292d98753f177c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:2ebe7c7d0e572e64c83392f8bb3f5900a29b7926096976b3d7c577e202c1fd20
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:c1ecdaa98f970738e481a433250fde544115fc74067cdb0f9db41b33e1a264bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:68c119814cdfa3d584cbee3e21bd44e5e894f1261ec9cf9546600f69e51f2d09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:36d1b95002e04f7b3402b61b27448e3529b882a32326cbeb1339a7a792ba3e61
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:d2f54048dd45aa3876d336fad6798174a12641c44cdf29ce4b45490efd706ded
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:26163a752c32c311ef633418cc651ee10b9a9b3dd1a76973a1f431b2b79eccd5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:6f3e041138cb4c58436f7e3e0271679a6cf849392080de2c88213fe36ffa68b4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:46f415fcc210cbb929922a4398b260a0db731f791a9a986100896e6af457c1b7