Sign inSign up
Cosign

dhi.io/cosign

Cosign 3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-dev, 3.1-alpine3.23-dev, 3.1.3-alpine3.23-dev

Index digest:

sha256:c03e94c3bcf2bf91bd3fe0db67f437da399a797299e806e4bb792dd1f1087d41

Manifest digest:

sha256:d14ed024a2143d38d63abb4cedd08109cd4fa10bb0f941c8a0083c0f40ee055a

Size

53.69 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cosign:3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cosign:3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cosign@sha256:9bdd70f5fb67177df2da76261f8ad796f82a4ecf679cc4b4cb8d50af3ba90f20
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cosign@sha256:f90546468b8f0d1f438f566f080f7693b49c19110d5edc36636e79677206ba1d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cosign@sha256:c4454b1df41637353541006e6df9f1d9812c90f0e85b0eece64d706361e2f39c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cosign@sha256:68737ed593800a03672e1d7b7eae0ba923e47ceac78f2b490cad006b925bb348
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cosign@sha256:329832ad4e053193eaa5bb436c7575bb6f211a85aa24252bfe398febe3b4e171
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cosign@sha256:c8c503be9e4663dfe0f9a1f4cd9d0d20f5230e1c1f4afd80f52425f1aac86b39
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cosign@sha256:2594ea3c90bccaf1c05cfa73cb7c5f291e2d1fa00d07d111dfd63cc7e3d6ced2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cosign@sha256:2c6b7390dd2f262adee551c68def82d7027c57214354cc9a1aec8b9430ff2fa5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cosign@sha256:8ae78024ff807db2b48c25bd581364be4fc8e595bcc996ec4cc20118459ee060
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cosign@sha256:65bc9f30778bb1cba36757c62462d0fbdc64ed922ad0a2c571dbb5928d264f17
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cosign@sha256:c185b68173915a19c93c3a644d76b20cea3fd8464e8409255371bb80a66d7e85
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cosign@sha256:a6642f7b4e1bf65c72c79d0a44b2e00ced83d14adc8df755956c6266820a46ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cosign@sha256:59e9eec1df226c90be6e44d9c3b4f60cf23eee90342583d1ff93b8e7ec4a46a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cosign@sha256:2eab5d8d67725e63fe1fa6ad03196ee9f07c0e915bf0dc41b2b050ebee063555
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cosign@sha256:7af8bbf862a4a2b7ea3c15638bad4e887297bfc540f8b2e72c9ab3fe96f85ee1