Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.23 Base

CIS
linux/amd64
alpine 3.23
Tags:

3.23, 3.23-alpine3.23

Index digest:

sha256:b9d3f74989db66757080994a59c89268bd2e72e83b5d4784969addec65ab3530

Manifest digest:

sha256:f6dce37349cb14ffa49f59b6890aa9b7f4950d7e1ebc9fc40a35b00c823f60ae

Size

1.00 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:df1c3c1161824ed028aab98d945695bd940d8006fd1f32d520dcffadafa99242
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:34b9c4e07f9f6fc907d6edcd8eac9c238c8892f12a8032d2d9f2ac0bc53878e1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:34f024fae807c6b31c849afec3a98b3cf0d8e199855ff808e805dfee51d3df7a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:817dfed6f6b4b4bace9f6a283d9c168c5544706deb0c23e4f431ffdeff156acd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:fdb9a503e247306fd87fbe644e4b4db835eccbf52fc217ba2adf0ea4daa5069a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:8f4d62f139cdd7df81f2b95d7c200d3d3eca60027cf5d69aacc950dd0dcbb9bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:e74c30e5845b0e380ff0b553c4ab4409536acd2d8a75e3a11291e373d6d84cb3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:526df1063eb9ac2956302a5d1002293ba70c2e9f943d25ba78db9284bc3ab418
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:a306771b6988cb29e34746575595a43b301ce2d7789c722c242d5239399ec74c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:73fa9c7eaf93e9367552e185509881095225339ad2d322f5330de59b678b2371
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:31b6260e8e184a47bdbcc7df06cd52ebbaacb65a41cb3da4c79f50b0e75886d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:0665fbfe5a02bc664237c90c71bebc0f00f925113ceaf7b0eeab94643a38ded8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:42df5a3b1a1c9bb6463914f91dbc0a73538b92badc8d597a30136bd59ddc0c90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:ff4722db78fcb265e2aa8c98520b16462291064f1559c7dbe6027d8b142df08c