Sign inSign up
notation

dhi.io/notation

Notation 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.3-alpine, 1.3-alpine3.24, 1.3.2-alpine, 1.3.2-alpine3.24

Index digest:

sha256:b0584fd0b5765218da2f4496675bb9aef09536ddec0a6896afb2630f343fb3d0

Manifest digest:

sha256:aa6304ee9ee4912a630f7a49f5c7bc74d58b0aba878f50af3114f3a217399fb2

Size

3.77 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:0089fbf7421ba8f58b09b6f719318094228ba5593e9f98542c7ba88ddd0048bb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:89fb33fa359a2e765ecedf62ec090a14df8f22bf1256bce082be1455d3f8607e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:bd12e8ff619d1bf51b15d0c19b92139f1aaedfdae71bf36d6f20f265a47a79ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:a846d60baa72d2863c2b72c5e934afd912328b5fbdf80833eda4f7042f0d8041
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:8a0b44fa61bb9c4b8a2df7a563e9508ecd2bb36f785cb01c38a091fee0ace628
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:72416fb6877946ef83ca9c2f60dbca169878b4c4b228c2ac0f65ecfb5bc38570
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:197961c6762479a861e10364aea218c6e035c523c561d5974e0f70ff186ea6f3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:2f69cb3a66f10b19f1d297ba5fdfe6949eae478895ab4d9d1a83ae1327d4e52e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:0c0132a40b6167e8107238a461b29fca733a36026add7319e26cee7d9b370cda
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:206b92bbb42f39d46664250b91d7fc3308d2f17fa31f498558fea666b9355313
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:f81530396016d7224876b35f32e3dfb01e6c354cfc53cc456511b122eebcb756
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:fedecbba1a1ba53f0d7c7bc5809971ea10966b69680a80be5b9affe73bcc5d69
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:0dd2cfb7177a4a67d61e9df8a808e05d5ecbdb642d5c3c96f3f9a4bc79ad2fb9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:cc582fe339ecb6abd16fb46e2219445f6b717deb7a7b1bde7697f479b2fd57a6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:6f3f3f96f313e0dd29509e41a2bfce72656946390a2f7ddddab047576ba1fec5