dhi.io/build
2-alpine3.24, 2.26-alpine3.24, 2.26.0-alpine3.24
sha256:c79b3a7f150dd40e7050abfff1f244697820f94e7f6a9d6198b0ad7404c54a57
Manifest digest:sha256:8871ce4ba46a6fe589f7f299cd1da9d7f79eb98c8afa6680855e1cbb77a9b370
Size
18.20 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-alpine3.242. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-alpine3.24 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:2b541dd73b4b77efd3224c6543f429c63b961cd0b18d31264408505026c0bbfd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:8a76e9ed92074a04769c676200fe5160bffb43d30894dd4e002c2b4e5c4c6745 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:66718119c774224b8381b7eb3b5eae5de0cdec862d45ef70c48d3ce04466038f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:a8e13edcfefb7079f3306f8c3a27a8abf1e45aa3dd94f8a4e781c5689016b012 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:4b98ca72e00e7b8489d00800f62ff807da2beb7bf477d13a416c921350723da8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:639cf150ecf6424c3b27161bb45452a0f9e3fef8f3e8f7c2d86816b740390d5e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:2e87db63e9f1f6b69d5f64e4718d8ff1ebb02a16c3c190b0c3ea560249f2f7fb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:6dabb528c4d0e846d981a4459982293156a0baa2ef3859e6a2e1064a4b29b667 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:e7f98157466a75e05ee240ff66d4b7c92c9986b327add6b9e97b40fc7c119e9d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:7ecf3910fda4dd6402ba5f14b626e3aa577b7d2fadd673f5b82d45b3cc2e184f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:64d155085d34ea45df872d92b5f66e5038fc161d5faa19439ac6313f4ba6a757 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:627f36d418eb2ac1fa077a01f082ec482fad13ab68dd4b4115566a383cb8c6cc |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:98c427f7f0ec5d26a12d6513b7333f06a4e1dfaf362bd9eff9e623346a70ff36 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:44a52d58035ca0782f6218007b92da41b57ee8c4bd5a882fb58efdc7bab43368 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:cd2613f4e23323827165fa6a3d275dd02659d7c6db05c70c36ec4d76ea5b6a7e |