Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.12.x (dev)

CIS
linux/amd64
debian 13
Tags:

9.12-debian-dev, 9.12-debian13-dev, 9.12-dev, 9.12.4-debian-dev, 9.12.4-debian13-dev, 9.12.4-dev

Index digest:

sha256:62dfdb446e5a9bcd251668b121679ce3c1e68a71dbb0cda93592e8c3d7c2f106

Manifest digest:

sha256:4f91a61a550ffe9ca6831c3f3493aa3e5181c9eda2d9de5a362648652490c196

Size

517.58 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:f99eda038eeb69239f1388c117046c3761fcb367563ef2a6c96bc024c118a5af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:34e5f3129aa30d04e9f2dcfb371809ff8b6f06809f0a17a92624f49f32f42895
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:0aa469e1ca1642af97c7b5477cc898b848dca122ed54416070c96f41b847f293
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:3a673a39cfb41f47012d14c05ed327332d6c9ded809649e580562be5881d086e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:aab9751ae99d2f67b88a53fa8d4d1589ea6f1a78260448ba3a8fbc2d5e1647a7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:293e88d72a25aca424f44d7a2ea47630cde7c355d68ea4668ac16d203ddd064d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:806cd4055d89e804e420c7b6a49298575c3f9e8de1a1dbfc2a8c7c9f60561e98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:0854608a2b697aed217d1364fd19b2721ded53981e6c44def3e8e22060ae8761
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:078051019408f31f1536870ab9465db2f69f53f1dbdd96fe03ecd02c992a1cd2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:3d1a1492b93bd6865049b08768004a002d3f26aa87499fcb9abd46dd98066f30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:fdd58d7c4dacf16bbeef026495b9021ffbf7d01c71c17aa6644b803b0fa77b23
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:a29693d16154f9ba0909fb1a3e27a4f3b3cdc7bb76d666cb2d1e51e771cd7adf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:aaedec88d8fab92a0bf28f1ac9ddfe4a71cb7fd8fc01f877b0ac83ac41e78ac6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:00fc7712208f09bf5a730eaad0d9c98d8ac45623070a370bd3f2682e766b272b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:3b6ea8929e6005907df63d792026fa5c766cc0339ba788cd9432656172a46f56