Sign inSign up
notation

dhi.io/notation

Notation 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.2-debian-dev, 1.3.2-debian13-dev, 1.3.2-dev

Index digest:

sha256:1a9569a41780c858a3677217ba30dfcd33c04279cc94122db0cd6c78b50a2fc7

Manifest digest:

sha256:5aafae9a9b3c33e2a656859e8280bbc1741b1803504c8c3bd7c00e2d90352257

Size

29.73 MB

Last pushed

2 days ago

Vulnerabilities

0
2
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:846cd0cea23d12d2343671bee639309b633a1d880e44ef5c1c11a4bc7f07aa47
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:632e7a7fbb43b8df1685293d91d2fa54f802c888f8912920ca0675e16e64c2fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:68a46236fab59bd95b284531e815b70d66ac55f9137d08f839b0b3c390ea041e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:f0daef65a4786afcb5caee7e98594b6f262d48e8a9601dcadeace761d87ac03c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:509307a39e17ae1a62814d81a236f33dbfc25134e7ca1caf368a4d4a74e39bd9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:28bb298c3a8d89eda3a9cd5ee73e1a972abcde7376037dfbabc8acbe3be10889
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:331097091357fdd3eaa500c7fa7716b07080eac05111a57e3dd0df4afe6615d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:78d583d310575c50e40a5a99eceb9dbb575e04d2bf40f8512d284ccb2996c055
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:e2ec8be0925ea44888a6fb8ad3b3bb67426a83909cbfc884ed5948d9ff08f273
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:4af2c5477ba05cd7e1f613b4bc8d986824f3cce5e133acaf063303456a2e0165
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:0e36b6248f3ed0abb3a658e1892fa1e268822532f96b94a3930ed0e7c27bc616
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:4f08f2a40f21e93f72f52d72c2949e3d86aac56ea4e75a99f2717b497c457bdf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:e1bd17a601e4f881a364b2e25720b7277bbc61e748b65b94c7f53fffa103733a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:9df74df1a12f081815bec5012377fe8c9c5a3675595f99b050c8593f1aaf0753
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:c70cbaf2f7025cbd3fa99b14fa4f7326f67a969b26399e5317b65a1cfa4a3021