Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

9-debian-dev, 9-debian13-dev, 9-dev, 9.14-debian-dev, 9.14-debian13-dev, 9.14-dev, 9.14.1-debian-dev, 9.14.1-debian13-dev, 9.14.1-dev

Index digest:

sha256:1e9f835e8414e6578d37c24cd5b0d50978b20854c14b3c22102a68a0393af092

Manifest digest:

sha256:eed3ed735a4350fe76aaa99f373d20493c78a0fafc97c9b8621ef6cd10c3726f

Size

523.05 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:5f086c364bf43cf31b6a910f03abf536466bc7c7b845aa0802a94e1b4e41d986
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:772d4775ae63a0565e267fffb6b507f623de865a273a01b2fc85ea24aae4c80c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:a30fe08d75fde4dcede1dd584e635cfbccb849dcde83fb82385da2df8d07ad3f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:fd01b28cf0c1f3c7986500770697636152636f67ffc47783afb261fb105e8556
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:35b8c15ad0d64e724225384de9e9581ccc901ccacb83c853f34f567b0c60a2a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:5215ee9b56b727707554446be0ddc3650b4281f4f2b2d0908160d2dcff07e9a9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:8afcd4785c6ab54a5c78b1a4e9f4d8853142a41e858a3ff556714ba2849a834e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:9db0ecf0163098eb6b8364e3b44dc6501db3d4df83c9238dd43ab75d9546da57
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:e8ff22dd8a5506ea2cf0bfc8db298247b32728f37a3ec2ede2d7e817b42ddba3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:12006b6a9b706c155b7c308c9d722500e3f404160ea5ae6a4a22a5f861cb4243
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:e1e258e98bd61b90a766cb4f7ec6324794241a0df3e89d0d79ad4a05d1cd37e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:dd62037fae13352cd0304e380e4d1c883b01d5dc62f7bec03bf79ad5becc27af
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:8bd0f3af4e7d0eb262ce1825cb9d2e676360f2ac62378a6410683ca1a4a00fd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:dde9cbb432d0f9b2525f12d8e506397ed4359203af5e0c6296cd8baeb341b275
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:b0b57837498c64c7bfe7d1e63d8416495580172dd78c9c37adf948954a49c658