Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.3-alpine-fips, 1.3-alpine3.24-fips, 1.3.2-alpine-fips, 1.3.2-alpine3.24-fips

Index digest:

sha256:5e07ccca82f804389e3e8810d86b1d4927f9d19d603a4463302d22fb8e0b0464

Manifest digest:

sha256:72d3c4bd2536434e12b9c25a77eddcdfd2b1f14d194e7696147f204d78898382

Size

7.15 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:7e7932f3ead03c47a39e13c4009fc4ed7257f0a6dc7721c4714bf6f711357034
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:2e7e690889794dbd3a42d49136f018daaf78b4b86821d9af2946150da6ced4d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:fc679b81b30d736b50d0944520fd1fa6fd7c67b5f639fe5fe637184bdd453b35
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:d6ccccac872477ddc6751edde516364fee9746a4d8b3839a4ac8fab9fe73823b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:5617771ae45b256ff58bdf66945a386f483e5cc1a821c96501c7bdbed7cfd006
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:1b4e86ed3e7c3e40344559bbd143fcf2a8cc0f5a1682c9c0073cc2de6aff1263
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:4695d502572bc979cdb5e35f5fe0230e93a3813d19235cb07d18bbb8e8e63127
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:413a09926ef5069bfe2867e4af3277e6b7452253bbd68cd609304e9a8a380da7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:7678d77380a45d05bd5e01aefea1f529f23752fa384fafc8a48be094b00889ef
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:fdca36fbc6942a6ad2a5b1d58d66cfd533b34360e7246eee6034972360366468
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:2f2308e8bb9bef7cd9ed37012f7fbaed4f363d85ffc6094ec7d9325e8f580ed5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:843493a60974c3d9a781336bc828abc039c1a08ed0f306544ffc7787de96641c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:401a212db9b0661812d7bba61bea9b3c565ed30b939ea0735ed2c5f1864e0a77
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:4f1138e52b7b9bde0892fe41471e057786ba7aaf8e0026f8333a04a423dc1630
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:75c18e7f3238b7431b17c7167fc2850982deb84266f71c5cdbb2afcffa45c05b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:bf886e18f1ed58ddc3604649473737697fbbbdd977aef883e6927b2b1759fbc6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:aa1ab2951dacbdb4d5c1529ec7d61529c83ff2d8aba3d2e7a31aa95aca97e23f