Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.3-alpine-fips, 1.3-alpine3.24-fips, 1.3.2-alpine-fips, 1.3.2-alpine3.24-fips

Index digest:

sha256:0a913a32a0cf99bb93474ee2d497e3592b7f69d7f36fa278e470fe3f1543fe3e

Manifest digest:

sha256:3e443c1e3fcce19ea9475b40a1f33d8ec30b75cfa217ef0dc39b60cef2d487a5

Size

7.15 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:15e4168096df41fcb51df32ed824a50d464fbb5435e50a275c2e2fbd1de588c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:d978a68c01c70fe4323c61362a42ea22d4d2e61a177cc6da175e1cfa84a3d216
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:3e56e251f48734ed029bbd9b55dd0a697170dfdbbf3ec4142b43692abba9b62a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:2eed72660b0cf7f8cbfc3241ac9d9beae280fd2e55f9c4dc96c7457119aaa9d7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:d26b2ae22c0c77ce66aa8f135390dd2fdd6bf8d46331b1bd11a75644b5ce37c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:12fa4500c69b72ff961feb7abe0b3bd710ffffc8811d253fd11216592a41cfdf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:d55da004117f8e8774d7fd71eed5f445d3add22cda21345e2a034608bb7795ad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:a99dd470a257773d1637937c196f703d82ff5af2f385bfbc6c3a4d56bff63da1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:1f8a8c1d16b2de97092d046ba21fc9839b6d05659ad2e82a9f08587dd6ebcba9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:a4bb4829423edc4dc30e432f808f824b4feea7be57d23556e087374612904f91
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:b3936dda21427cff40c474721c25da6834bb0d78de55924958d9b2134af99c41
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:0a24e6add0843d74a96ee517ea923d3b4af1ad7731b78ba91e60833a88b2a05f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:dc82ff3fa4be595781aa8a42636c788222c43042862848acec694003324a64e8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:07c2d220f228262273dce3f3b37a1873e23305d5ec2408fb5b5ad232c04616c6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:784086f4251e67c83cd2fe86fc4add4371dd59f221c93aee3c6a8bc93379a54c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:8d7e9450a46cd00194957682b3b64894e88e6f79883a927c42909b431c1be9e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:058de24333169363a77b1dfdb250f04e69daa33f26710d2c543420431eb88e72