Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

9-debian-dev, 9-debian13-dev, 9-dev, 9.14-debian-dev, 9.14-debian13-dev, 9.14-dev, 9.14.1-debian-dev, 9.14.1-debian13-dev, 9.14.1-dev

Index digest:

sha256:8ec85586ab2ff094938e8aeceb6d31311710956e34b3686be9dcad3786eb4f97

Manifest digest:

sha256:ebbbb7a219c3b6c5a2c496ea525901afae92f4333b384cf0755b22d4445446d7

Size

523.05 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:400e8ba6f6913d2b931e5182510dc900ac0a5ccfd20264be761eec6a9ffb7442
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:7a610ee242c0d7be964e4a834f322ff832084c637402e628bcdf3adcfc702184
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:4d9beaca5182a8c3897ee75b9079299b543e7fbcc5f99f78762830c99c648136
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:2d8083b7a9887a1564c0c2a16e555eaae27328e8b12883c2b180cdb34deb88ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:1abf6714c5e9c908471ee6a2a959d8c08e98984384d839c7606fc1b75f112238
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:2b587aead1a64a40c39cb45460899dd5bb2ea58f09706ced3c5ac118382b23e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:5447f9badaf76c9b173071a1fa93aadbd6420b98857774c05ee6fcd1ce8922f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:227b4b1ee28f71105669b48f11be9f8328fed31775df7d7599812ed8856231e7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:db07ded83363e5fa8c80eab65c46f0700f1242c50b4e7c69cea41f0e83704530
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:45ea0dda546d98015ad022fa3418aa181e4e9c00454a3b7d90c5d90144fd4989
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:8f60711ab1bc39c3484ddda09571a699b8befd63fed80202b54d7047bff4f54c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:bd19850fbb0dfe9b6d08f48c9029f241f4c2279c243c11a2ebfb6125c10419a4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:7e279c6304bd1376c30bf5094f9536f8d1105a458dd607cfb5888e28dfa77d6a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:def1ca19b6e910b800d48a76ae3708fa02cb5c6f651ecf93c5529b0a6ff138f2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:94081e9f2259610b9fbff8e905c49812a73f28e0a4c76cd7af01323abab0c82d