Sign inSign up
DHI Build

dhi.io/build

DHI Build 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine3.23, 2.25-alpine3.23, 2.25.1-alpine3.23

Index digest:

sha256:504f1a449a74a72be40e4dbfc1b89033598677497f59f9ab89da46d0ba35a564

Manifest digest:

sha256:4b566fbd6550cf972f135eefff123387a4692ec728fb3898efdcc2e8d819911c

Size

17.90 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/build:2-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/build:2-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/build@sha256:51193f74f9897f59c395bfd1f61188ee24ef3d85fc323bdd186dd914ad895dbf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/build@sha256:be0fdbfb940545e6953fc0e34c63d0f0482c003b41383d14b71b8ea85e0822a6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/build@sha256:e6d9308944493ef473f4ec25e1519bff00be66c666e78f98dc65d59cbc392729
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/build@sha256:975c251e5f6dd24e60984a2fb8d8dc5c8eb3c4d495f6dad422e6f9e4bd937e92
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/build@sha256:e21dc99ad3d7cb3ff1f0c86dda02bea452d83b28c931734a87cb5cb7d118577c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/build@sha256:7d3ef94c7dcdd97dfb9a38b62e4caacb053804ed351cc1f842c1997e709ab29d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/build@sha256:699b1723cbf8f982f6e5e9d4f07f78762faad304a5c29d91483e50b9953acfee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/build@sha256:f24e2dfda2f134e06ef5b5f72bd13722f5d0b281174d099aed06e8f2a9d9cf4a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/build@sha256:2ad96b47daf409950c584a5e85872b529544eafffd316320ed2432cdda6e6a9c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/build@sha256:31139d97718a17060ba652e61cbb745078feb0273de41f98457d1049f9174c47
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/build@sha256:55a6371054d4bfc3dc19d50082426427de40d60d6a3e4ed447114d6184d355a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/build@sha256:06987665f86b799da0bdf850411f7092e2294eda59222fc62ea80131a4afaa6c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/build@sha256:fb2f42993bcbe64c86ae683dfb43560033dacdff9753c117aa826de41cc747bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/build@sha256:1400c7a0273b67a9c06994403ce5bf7d33110f206e9c693998b3702695568165
SPDX SBOMhttps://spdx.dev/Documentdhi.io/build@sha256:d619895b9bc9c5c8b45e09514b6d047e12cdcf868d65ad63175538794b601cc3