Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.10.x

CIS
linux/amd64
debian 13
Tags:

9.10, 9.10-debian, 9.10-debian13, 9.10.3, 9.10.3-debian, 9.10.3-debian13

Index digest:

sha256:d6aad75aacb880f3797a21dbc97ac03b037dcb6c0b864ca1a65f1c757d5e6f76

Manifest digest:

sha256:dccfd885fc015fe6f928189c7effd2f57c5a954a680de09bce049485ce8b4a83

Size

415.28 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9.10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9.10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:63fc5d99ccbf43d1721044805129e9acd45d2a124ecde5ab932439b20e00fb2a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:3f7dbd43d1b4c1eef6ff6be92493c3a88ac0620a649fbc1d858da52259a5ea1c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:096e81f4508c06c5e4ee5a45ef01cbc5f819c042c974b71a4f02207d805f58ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:c4c82aaca44e3daf440d8d81cee723423f5ac5144d78aaee83a0d7cbf928bbc1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:7f5bf8ee77595e06f369b678a044bed1d1d59e2fcca6fb4123b7868c04f3e3ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:e33c3fe6af27db00af2f911d3a307c9b3d40c86f24c1f44b9008cb28b05c8655
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:998e6193e1cb324e8c2da1531f3c4f331e8413748bffa8a2818e04a9a5b7c2d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:c1bda01227b4f529b4d127945c6cd253eb1fd6c2150e2cc1d711b11d42ef1706
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:f0bd0da6458b7e749b2a042835d16167470b135c03d0246638c848435899ccb1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:afb7512edb5429bf3cd1c08495874caa831ebcf8fb15a45a134c276ed82364dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:adef6d9ca1cacdb5fff7eb4c61e630f4b2c5eefe8cb25ca94b0984ddb24afce5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:d8868a52b7df1bfb7a9519033a8945e02b6406bb2fdcfb582ab126395a310e66
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:d0941ed4deb5bd8b0a4966b4a0dd26b975779bf80149ef3136b5a0203974d765
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:d8dcf0a9f9f79ab0ce9a46843172ad1752d836a07da427fde41ed9c75f06ce6a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:c31678b2cf9b3fe546d9e1c62226cdbb6cdae4ae0414fafd6970973a495939eb