Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.14.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9-alpine-dev, 9-alpine3.24-dev, 9.14-alpine-dev, 9.14-alpine3.24-dev, 9.14.1-alpine-dev, 9.14.1-alpine3.24-dev

Index digest:

sha256:cf31dbeeec3d8c920fdf2ba5d18b1de76b5aa94e950b29f9cc05202b5b6bbd29

Manifest digest:

sha256:3a498ea8fecabae208174e408095de1ab1c43d9db3a98ab60ebd4fddb1144166

Size

500.38 MB

Last pushed

3 days ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:7b4fc7227510b61d978505ca41b59d56d5a4b6eaacfdb533a19f0dcbe24dac7c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:bd9ab7d2ed96ff96df43d3a7707d70e25d42ec3c5cb56b58ed38cdf3d5193596
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:a9d0cea6eea34beed691a22f9ea68b52b3d1e0a1aeb3d39e796d07e4be3de9ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:250a13a4bb65ee8dfc2aae44bb085f093d49c1809286c7d3ec4dcfc1ea965c8a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:0ed1bafd69a30f4b62e778ff88144b25cac0460b5a589199f36d5017e3737d26
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:3d5d1b6f05f631cb9b9b3d0e81bc71c42f1d4f4501374fcb970f8ee0086114f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:f0e83714592b4f5c1409aee44463bb2e512adb037e77bcb4c1267835bc52757a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:d38d1c414a1e5fd1e840c43a387186613caa242606ce65148c116da7d66e987e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:c617b5b1901dc585cb18797f78f8d7903c9adde817aac8ea3bbc6b2019b31fdb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:a9e9179855a178cde7b30bda2bbe5e589b5d67f736c1f2401c0e270fcc73e3fb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:90838b67557ce49e29c6af6a8cdf2734b47f5cd1eb01709bd800c09accfd7cf1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:984399485f25090c7aff7e0d0a44b71d9a9aeba7e2f0e9efe40f95d724eb7f9a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:a99195ec043fb6ed887ad589ee452eb8d57b1b4468c19fe1369056df159d5985
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:224ec4e2618adab156d1741531fd2900f8dcb6c1cb513ede91d3975ffa64380f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:b1b7f6d9a6fdd48e4cba0207c35b7b03d3324a94784985177f8b4c9e2c4f3d63