Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.12.x (dev)

CIS
linux/amd64
debian 13
Tags:

9.12-debian-dev, 9.12-debian13-dev, 9.12-dev, 9.12.4-debian-dev, 9.12.4-debian13-dev, 9.12.4-dev

Index digest:

sha256:a078eed5719a51829f9cf821500780183a57b4301fe6db5bb7c4f18361f312be

Manifest digest:

sha256:fb974963e2928f166a7fe2f78ad4c1324ff3bf84bd2b46c8aef33e0ed980444a

Size

517.58 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:2c69301aad1f34987dbe2c4594e24bddc11a6a5002fdcf1637eec466b3beec85
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:332fa5214820c933d7262edeeb684d6db43dbecfcb5861d2921aa7b7c12260a9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:05ca129969de69d864be9ca0135fe0c41366d60d5305b99bfb7ad4c65c7f625d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:89a2ff32f84c8f78da383c09afdf267a3875adf7fc41b6a28ca710b2216cd718
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:53165feb516b4fcc7ac7dbec85ecbba820ba01eacc079ade659f9e6423a1a038
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:c6e81e9123fb8ad03f4802092def36c9c1fd37bfc6979575915d95bd4135b8db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:a968ca0dc05b425a8b3e851a2d0eee557d680a122399977e7b33779daa226fe9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:c3e1226c2c0df98c313307fe7390bf28408877e3c08d1449538bf70c6f8f5a5c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:63331ccdcbb32819b803e5c6481c12ca7b6ceb5ff1e2314d5a95b3ff63ac9628
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:bf0294e1f808c38e4e7016edc42a209a4be9f1d19527705b2483b301399e43bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:b77d3842107e9ca227c93c9c68a51a578ddfcd29eba11c7aea04e72b775ea6c6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:dae304e10937075437dacf81d8c63c5e885a18f8b0f5881bba99ca50ea9453f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:d394f775a3e1fef163638bf2b2a37f2ed2eebda08ccf679e01ee679401179805
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:c0f188ed6687013ffcd1de034af588c143eb1fbc883760b9ec09dd75d482961e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:d0bf26e9048036dd2ae796171f51db97b2a5022c7a5a1c185e0dda690d11d8b2