dhi.io/build
2-alpine3.23, 2.25-alpine3.23, 2.25.1-alpine3.23
sha256:504f1a449a74a72be40e4dbfc1b89033598677497f59f9ab89da46d0ba35a564
Manifest digest:sha256:4b566fbd6550cf972f135eefff123387a4692ec728fb3898efdcc2e8d819911c
Size
17.90 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-alpine3.232. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:51193f74f9897f59c395bfd1f61188ee24ef3d85fc323bdd186dd914ad895dbf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:be0fdbfb940545e6953fc0e34c63d0f0482c003b41383d14b71b8ea85e0822a6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:e6d9308944493ef473f4ec25e1519bff00be66c666e78f98dc65d59cbc392729 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:975c251e5f6dd24e60984a2fb8d8dc5c8eb3c4d495f6dad422e6f9e4bd937e92 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:e21dc99ad3d7cb3ff1f0c86dda02bea452d83b28c931734a87cb5cb7d118577c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:7d3ef94c7dcdd97dfb9a38b62e4caacb053804ed351cc1f842c1997e709ab29d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:699b1723cbf8f982f6e5e9d4f07f78762faad304a5c29d91483e50b9953acfee |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:f24e2dfda2f134e06ef5b5f72bd13722f5d0b281174d099aed06e8f2a9d9cf4a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:2ad96b47daf409950c584a5e85872b529544eafffd316320ed2432cdda6e6a9c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:31139d97718a17060ba652e61cbb745078feb0273de41f98457d1049f9174c47 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:55a6371054d4bfc3dc19d50082426427de40d60d6a3e4ed447114d6184d355a4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:06987665f86b799da0bdf850411f7092e2294eda59222fc62ea80131a4afaa6c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:fb2f42993bcbe64c86ae683dfb43560033dacdff9753c117aa826de41cc747bd |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:1400c7a0273b67a9c06994403ce5bf7d33110f206e9c693998b3702695568165 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:d619895b9bc9c5c8b45e09514b6d047e12cdcf868d65ad63175538794b601cc3 |