Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.24 Base (kit, dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.24-kit

Index digest:

sha256:520e3d27a57101ee1378f842c79cc67e709801987574bf510a6887bbceadd6e0

Manifest digest:

sha256:ee4859ece2f10540b1a2e1687d22b21262dd8a59f7ff7cba00e0c5f7064902e5

Size

9.96 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.24-kit

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.24-kit --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:84761abb94e41c53f237d7be045d2eb55714cd486a24ef129536f734e6eac00f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:c375482127ae6b585a60a404946379f462849b06d7b7be72a6769e94265822fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:0fbb4e1c79dd507516092878107780701276d86619137c57934574bd3f4868ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:6e19c9686568377d0a8176538816586d6e6f67fac319544496586ae682c88a8a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:c6cc172e133a9e79a1a3a1965fa526a2460e7032d48acf15d40eac2a7d9bc3cf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:a7d52b0f086b355fa2e947e2778d669c3746af749f6b8a0390fb02617a5c2762
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:d11bf2626f1376f0159c5ef96836c456deb3714cfe85ff521ce2aa753160a987
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:0650f085f115bf2313a0e0b4e00289722be2f3ec50df629020272cf5259b29e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:a56fdf6d6cfeca8ca6b744084d713fc16472ee406a3e74d8d0c4acbfd5b8e42d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:e8572e64ab426603b68ed773970ca1a932b77a144d1ffa4c52d272920c7a1d20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:af7302cf731929f71e3d765494e83ab6ec7341b91a3894c6af7b742c68c1f60f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:2316306c7ad8ad6503ec04e0af3a8568388aeb4f13af2cccfb2eea18b3ed5a45
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:61090dc251afe2a6098a74362ecd59889967f331ee98ef9568d31fe964a2fa99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:fb9617fa6fe598bd6fc3427939545f4babee05dc0f5a266fe06ba79b1947a974