Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.10.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9.10-alpine-dev, 9.10-alpine3.24-dev, 9.10.3-alpine-dev, 9.10.3-alpine3.24-dev

Index digest:

sha256:02ea19621e8c7b2fa345179eefd5d54348868df7bf66f0ab751eb64a12b76f9f

Manifest digest:

sha256:135e197f2cdc6f6eada24393af049f85377d03906a29394f3b51cfe59bce1552

Size

398.40 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9.10-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9.10-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:f483a85c8eed3f63fc8292d183abc22086deb7d2d20e2506efecb4e4cb166998
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:1d471a3aaedc278caba3de9c91b68b5103d5db18eab955ddaad8af4bc145df7a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:d9269b979915f06044f76dc7b2a81d596d576c0d5a5d012de888a594a2434228
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:adaab8af87af8c9d09cc2d0ec5238e7416d451dca61cec77e3bd1aa5452cc587
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:28518692dd09ed38337fe744e91e1e23b8d37aa1be6590356b8f8ff4ac48e3d9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:3edc09ce4b8dfc1226bc71d0a8ec3252d2972051cd0d514fe709179d2adfa38d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:43012f001453b327e2c00c355b24bce50a62f1404adcbbdd5951c580a0635739
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:f650b4224dcef4b14b975eaee0b3c4dd57fa17e9ecad85e0cbc47a95d1524eee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:f1ec070cdab0171e42212e6cfbe4804ee9e172a63acab16867b1a2af7f49b294
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:3ada5176ec4ce8d82bac720c6211ce42c450432abffb0c76350dd6852f21eae4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:b204312d4c38cdd687ad0bf5f4ca111992ece1269a243ffe048d7de0cb466d9a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:514104be6e499f4e833c07074082ca3c851e7da9e31fcf8fb916da9f20564333
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:88d86db0d7253195812423b31edd9592d9464db70cea2639929cf1e050ac892d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:07143253fd1646edfd3b2bfb0e8e7f6c21198db52ee0e755e94b8736e699f7d3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:ef9d1602b744d1b2035182ec08b7a32913fcf0aa64fe2fcffea612419132ac03