Sign inSign up
notation

dhi.io/notation

Notation 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.3-alpine, 1.3-alpine3.24, 1.3.2-alpine, 1.3.2-alpine3.24

Index digest:

sha256:96b2a56502b1516b62a75488d2d65d5ea8e3451cae8815a8b2d9e90c99f781f6

Manifest digest:

sha256:33d217265f95556f4d65da9aebd192f80916264515a81378f8118df273a811c6

Size

3.77 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:e870c4a0e75ff4ddab302a15532360b3cf5aa70b8aafdf895db6e574fda9cb84
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:f6853afbd940d9fabf22aa9e950a4af682b2f1fc00b077313923ea574c641276
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:3511be98c21286ddc5be35f492a25e518ec6803df17c6ef80c5829ca8558bef4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:a310db362c82fd5223875fb710e8627f8f8852bdc8edb00873a6eb59382ffa79
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:b28eaae0229bd6973dc8ccb535c7b53d66ccbd5e00c6ee49736e354432101cdf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:4c101c0ac632cb8dcadc13cc0ab88fcf49f8616088b749f2681a6b94835cfa8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:64020405cef747e36b90559f20d794fc22ab3b96d5bb709bf96279cbb631c680
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:879daebb9a332f8523e44e7eeb55bbaccb4e08807af392ab494c5dadec6a0da2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:2dbbc664531677c533816901444556489b38b40aa80a40bab1d07fef25e44704
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:9668eb1ea850ce914f75fcd8ae5222b7333f985886c99bad782a5f0aae29cbb5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:8721d4439f05d72a7b992ccc50e1053dfbdffda7ae316938b650166dcc2894ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:ade207d9c3acad50c42fb7c886a7df50fcff183764008e12e00fd66727390e4c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:d605afe13297a0898ecd7112ab50968ab7bdeaa5480d443a037c09be090abc88
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:7db4f5e18fb004b5b2e2d1baa699f8f088183f11f3fa705423faff5dc234bec6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:4264137974c00ab3c679202a64128ca2d49ec2c514606721ca99d82d36fbf7cf