Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.12.x (dev)

CIS
linux/amd64
debian 13
Tags:

9.12-debian-dev, 9.12-debian13-dev, 9.12-dev, 9.12.4-debian-dev, 9.12.4-debian13-dev, 9.12.4-dev

Index digest:

sha256:9ab365cbb25c5d9226612fca59708dae90531b5df2e26c76500832351d6b6089

Manifest digest:

sha256:f40d423cc9e330f9032070bfde113a450bd88d8ef9675984dbc8f3da16851f75

Size

517.58 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:d0897c70f78d7531d96f143edcdfac4816c58af57129c4e0f28a59892d5b3ce1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:4be5f0433fe32bb091f0d5ee831dd818fed3363d312c1bb1583cbd4e883789da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:480fb66dce2d0195ae63776e5a31ffb4df6d3065ce33a3e81bce613241135219
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:50148223b95e6dfa6bb939a4f033ebcf8c89d04848970b6a7f9e060d2f38c24d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:02e87d72c4f6076257ed3c4f62f0ed6e4e34dad6fa113bf33bb21e1eb90c2189
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:4a5a61c4e7f3f9dde108e06dce8c2f7917d96cf283fb8403444fd69edc3a8a9f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:5bfd5236faa2c21d869c833066da6c44cf1019aa464519946501f0c291023369
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:59b8133f7d69aa4de8b6a2742abecd831fbc744ae97f9a3f6cb7528921998667
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:5e3c7de1e508c7248ac58c04b8e7d85c3ff732f5938bb81772527b8afcdacc3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:68c06cc5b87626ecbbf19106902e7c15c0e6fc3b3e79a7aab00170ec7c532fca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:bcc3a0581ceef5556922b4c795670f70c86850ab862a97356c377c4059d4e88d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:2f29fe25e3a134761e0bd79304048a1236080bc80c38a2e8fbc8156b903daa8d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:02d8944781615e0de884d9725ce9d5a98a07078878a9d0971abb8ea0f81d94dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:4457075a17ba90aaf2ed4012e5ecbae92a117824c582ce19c3a940952fe1d795
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:a54810f68654593b60363cc8b02c7e2dbd8226ed69f43cab364fc975839013ec