Sign inSign up
notation

dhi.io/notation

Notation 1.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.3-alpine3.23-dev, 1.3.2-alpine3.23-dev

Index digest:

sha256:2504ad126c01968b474d4a60f692872c7f113b447cacafa24f86fbc34443f40c

Manifest digest:

sha256:669affda78015890d32ebc43fc94a1fac59c658338f03bf77aac6bacad9508cf

Size

10.41 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:903d29db52ae389bab40144ddb875485e0caf23e50f7e540aad42435f1dc975e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:1c5205046431c899154164fc6598e8a4e85d32c2b8fe20784bc4524583a1cf76
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:6b4a6bc1670393fadd0f910e2ad66eba6745407d8c9857479bda5b12cc9d995d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:48fc608570413097d7d6970f228d9a1353de8a3fe80e133ec7b39caf516ffe6c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:79087d32bd45c496d1121a7623859b4a774a9fd690a31535875e6c4acd653a2a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:25eab820f91a80f3808bcedc6b3d0eac81f19bb3776cebf07069e5e19ec197e4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:76449d70d31dbc642213dac7ebb41f2be7d8f31d16f386b7868a2b25fdc1f133
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:a5a0add0e86660b4585fcd154315e86544b8173d9b1044c065f4c7cb21010250
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:c838cdc73acc89d1db3d0a4389bbd9a39536523b5bf06e3e6f59f2283c00cfbe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:964a75ce35bd51ee73804fcce71af231c69f4007547bd4a2ac93b41b4b00852a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:3ae07f589db834c3fe34e52aff5d2d7221aa0dd1a77dd2e5ae6e0c3ebb812868
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:8515e551c53d258466b711c0768cd390267a544b96109fab58db72487a113053
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:465027d861d8f1440d8ee4852648d78c4860e3b33ec836e4b895a19f4f4ee1fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:ef58a4229f83984838b48db1dd771baa413593902a0e1c5db279576e68504657
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:dbc52c34047052c2511937a5df3a072f2a076a9ebb657ecd53cf3c4ef85902f2