Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips, 1.3-alpine3.23-fips, 1.3.2-alpine3.23-fips

Index digest:

sha256:5219dcab32f7e74f600ad85f2441c77b79351807d81e108bdb5f092a65eaa0da

Manifest digest:

sha256:128593af542847a97e772d88f787f1c8e9b563a1b509b78f452ee710bcc4a7dc

Size

7.14 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:4dcaa9ee49b2a32d687f42b5c7f7ed8c3bc76382b99e40808870757b25f3e01c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:982e9eb1a87fdd30a68e19e6fba1833f3e355dc1486289917929d15358b8de0a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:4bd1baa3d209fc491a488094616c78ef93ff05d2ee296777b8581205b905a0bb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:e576555120874d44b7eb97d036b32738eb81e54896cba2df5b6b230f2f29351b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:714a49e1460dac769caabfe73cf20f19e485625607ed2319cdc31e0b66a97995
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:c0ed53fc707fe54c6218e6f19b1fe3840563b35c6efefa0db7f944609eba4e4c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:6c889d1e0916350dafc7fc2d6c88bf16f33747c95725e6893b9d42a060e64148
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:90a84d5debb2d6ae070bbe72f0bfd948fdbe727b6968b986896f8f5d2bd7d47c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:1934116ae115a22564814b502ce8b5edec29f8c1aae178c4ed927c3a25aca08c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:1527e4545f87d1cb426bf5744b3d2d68550715f7bbbfc6a41cf062cf5c5633e3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:b010701416ef04954c4150d9b24cfbd8efa6ed56e85076c3e686b65282d035eb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:8247eb2c09a1d2bcdc984b6d140ee2c049793877f880f28e0ab0bf1a28aa1e5f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:b624c2e659323fdacebb9309514d4ae1a760a5881fa1d16be46c34e0fa847701
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:5cee302e179bc4b98b0e2262113c0af1b0ad80d7b7c36cee17f9865327fef34d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:78af184e37710100b41e47c9743c222863caeadea22bc5d9ea98e3c1f0dc1bb3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:0274db2bb3a671ecc686e59c807bd17f6dfe0bfdd5d7372118b892eeda22db3b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:0abf2a1c73682386900c9125051bac2c730017c4be2c1b0f232add987c7c24df