Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.12.x (dev)

CIS
linux/amd64
debian 13
Tags:

9.12-debian-dev, 9.12-debian13-dev, 9.12-dev, 9.12.4-debian-dev, 9.12.4-debian13-dev, 9.12.4-dev

Index digest:

sha256:9ab365cbb25c5d9226612fca59708dae90531b5df2e26c76500832351d6b6089

Manifest digest:

sha256:f40d423cc9e330f9032070bfde113a450bd88d8ef9675984dbc8f3da16851f75

Size

517.58 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:d0897c70f78d7531d96f143edcdfac4816c58af57129c4e0f28a59892d5b3ce1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:28896bf928dcffc274e00cfcef686c1c05a7e2e90ea215ec0e04851220dbb3c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:2fda98f857c06254bd7b043953800cbdbc315627db89bae717985f744a60fe1d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:141e479ab6da9fda6643701f8e8310f09067f42ec51b9dbf8802b9afe404e069
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:02e87d72c4f6076257ed3c4f62f0ed6e4e34dad6fa113bf33bb21e1eb90c2189
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:4a5a61c4e7f3f9dde108e06dce8c2f7917d96cf283fb8403444fd69edc3a8a9f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:5bfd5236faa2c21d869c833066da6c44cf1019aa464519946501f0c291023369
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:59b8133f7d69aa4de8b6a2742abecd831fbc744ae97f9a3f6cb7528921998667
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:63f0705a82668da0416a08b8e2805a2c7b5891c802a84ab450d71bc76643ec69
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:5cbac3614e1d4f565cfdb154b77e16169d5552d8dfc26b96c1efd5df17687490
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:2740347087aa44034756c15adcad4f6055f36c0a6ec2f610f989218bb27a3df3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:2f29fe25e3a134761e0bd79304048a1236080bc80c38a2e8fbc8156b903daa8d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:02d8944781615e0de884d9725ce9d5a98a07078878a9d0971abb8ea0f81d94dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:4457075a17ba90aaf2ed4012e5ecbae92a117824c582ce19c3a940952fe1d795
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:a54810f68654593b60363cc8b02c7e2dbd8226ed69f43cab364fc975839013ec