dhi.io/dart
3, 3-debian, 3-debian13, 3.13, 3.13-debian, 3.13-debian13, 3.13.5, 3.13.5-debian, 3.13.5-debian13
sha256:0603a238b6a4f17cab91571ced6ca1cb8e2e888b077df0e43599610d744eafe1
Manifest digest:sha256:1151b953c4b6e9068d0039c5b98319b441ab38bdcbf55deb1ec4b3333bc125d0
Size
205.91 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dart:32. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dart:3 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dart@sha256:6a40f65e55f5bd32efbfa121b9d869f46d562afdc05f3a3e7e38898d3e2bcd72 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dart@sha256:377e6485b35e6b455fe4420636e6894f647cf0a0aad6cc91a04d01dfab2ba5ab |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dart@sha256:05f79b3b33e7881165d4ebe6247b96931e47e237730f5e397e59536af9f22d24 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dart@sha256:67fe6c85d72673beb60b0409b170c618f4754fef75728234c6d7860156232599 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dart@sha256:d5455f6636b505bec2c98793fbf946de79fc779135645770b445c1c3feaf3935 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dart@sha256:4d22da6f36748f7c0776be6f7b7dccc0b4ad56aa4a441c362901036c2620ef2b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dart@sha256:0af13f62458dade4427eaca52fe2102c75901f5e4a6ea5281252f38e3954abf7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dart@sha256:9117dc3923b30cb27aed943ddb20838fba2ad10caeccf54535db9d537b59388f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dart@sha256:2dd86121403510b297bf436745ecc5591d6fc8a444a05c9adf05b2fba60a607f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dart@sha256:72996e8e8a46d0cb36bfe18c8db62613a20bc21fa5eca93cb8da45141784aae9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dart@sha256:c5268304734ae900c246ef847994dcbaa0d265c83326b4897fdd091d9e357aad |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dart@sha256:1b2b9395216eb24998a8fa94d578ef613695b2ce501f647c1734c0054ee45a3b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dart@sha256:b511fc953e446b36e8a2501b0a9a99308332d7afa4736cc4eac3f3312d82cb31 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dart@sha256:5e8326c2c6c328921116b38e9753ec8f9c656c7f68c98dd20ce511a5bcedd137 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dart@sha256:df70a7bf083a541fae39b6fff0f507a8086b6dde4a4f592b30b7a8184cf75032 |