Sign inSign up
Cosign

dhi.io/cosign

Cosign 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips-dev, 2.6-alpine3.23-fips-dev, 2.6.5-alpine3.23-fips-dev

Index digest:

sha256:b2ae597811f91801600aa987bae9bb8b4033c317ded8508e46e4c559813a76b4

Manifest digest:

sha256:5d23b739988b4e86929d7239bd68bfbc929b3564121d585164ec7b0bd943a6e8

Size

53.03 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cosign:2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cosign:2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cosign@sha256:789144ef221d6d6af8407e5d0e475b2fece2cdd7c14ac19dcf96c80b0bf60f79
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cosign@sha256:776feef12d4c6e62ee3af43680c35497e186d70df93c9a62db403c6b8efe22e8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cosign@sha256:4f2bdcfe01be2adfe879328cf9c2821a0f4db72f05cc50cad01e18e53f22978f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cosign@sha256:5d9b77efbc2ecef0b387f42e57f7a5a6f57f94b42d385429ce444628a75f7260
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cosign@sha256:48ee604e73c3afadf1300c161ab794addb375bb5cc6558ddc8eb8bffd54d1f6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cosign@sha256:8cbb2ce5190b3ef03fdc6fc78239179013de972346c6fc2ea9f35ec8a4806216
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cosign@sha256:7a53bafd666f44df86fe1d9a95af505f4eac685679f882cd825cba09570a0907
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cosign@sha256:fe9a060be008f8a8f1175c372d39efe702a806baea8f0125907850746680afc5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cosign@sha256:df942b2ac30d6486d1e1905cc03cc7a6ace3339ee12870857400aedcb2beabe4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cosign@sha256:760603ba1ad658a7b9e05d3f3965e456607c2d8d01f85c2a8a93eaccf803c06e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cosign@sha256:e9d28ac67227fbfb0647b9d549cadbc850108b861d7317191bfb6ac4f78cde38
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cosign@sha256:02e2407d9ef197cd646bd696aa4dd0190c8e70090a3e30f18434fa5a8ce52d04
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cosign@sha256:b617e90f03165d9a75d517b4ba4cd8908725bfbb4578feca4e67d47a87344013
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cosign@sha256:101ea567e391f9dffbb37b8e28e1ed851907878f5788c33066e9f5186020ee9f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cosign@sha256:bbe0609aa608e4bb49be51a7a4630ff3258bde4214020fb7de7bf0bef134bfb0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cosign@sha256:4e32a4dcb7489c95c8ea9765e98647931c1074b802943efd4f6b68655ff6b988
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cosign@sha256:12a95437010c45856053a0d7456d0ad66294438055373db5a98fa4288af5b738