Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.3-alpine3.23-fips-dev, 1.3.4-alpine3.23-fips-dev

Index digest:

sha256:1d2689126fb1f04d4979fd660a931f96f0f03a043b400d51d7239cf9a24f5a49

Manifest digest:

sha256:31bca4047f11d8e271ba8f8f8d34363d714a614570066229093f3d84590f460c

Size

12.82 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:aedc1087d3ff6aec4812d9fbbe1f542c40101397b20c250d942a91a379f9289f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:9a4d454c1f4e98e9aa555993f7daa4bc4875704b600d76f83ecc1509535e0f01
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oras@sha256:84d8490ccedf89de6a38962d750b3a04752f2745e78c5068739e1f535cd72204
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:f1c67bfe3486a90523f2d47c817d6b584c81ebd42ddbbf2c8987a6c388295190
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oras@sha256:3691c864f45781c6bfbdc9950252931d1ddba8c81bd743d9bead835332229ba6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:07fdf861179518330dee9296b2969e51abc85f0e8212fcdac3c5c945eeb38330
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:40d67da51f6f37a836939a076e0563bf5152aee4003cea72d5173e466cd8b231
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:b6ccd1195ce9b480162a7c403f13bef1ededa34f82be4b99a45c57f992eab41c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:076f7430f9bf177019fbbb410795c013c870e278b850c22f2fc8946a4303be5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:8eee74d0145fe5f41892a1bd5a5aee5798173846af92f92f28fd20797ebebf61
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:694703dd3ade926a9181781dccc20ce332c1eac7d7346e3bf7559c869c727097
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:fd30150bbc45fbba3a67a22b3946ef26805d16cc23f225753d78fab0b245b262
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:fa866f9d21d4180f235234db86dbf592c6f6080d12c3d4c1e84b6b7e961160eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:37e9b4f5681cf6b48cb493c5c104a56d5773a552d94fc4246a7b44b1a628e2ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:e58286bf75cdceb0fbc11dcd932960c8bd9622187b98bfd5a76585a7e471b20d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:8ee70a8d70f7a93423efb196f4c832bcc4c86cd0fa394ad48f45b1b82a387bb1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:cd66a12e710a88de732156dab138bde4a15aded0334ccdf52122214032bdee49