Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.3-alpine3.23-fips-dev, 1.3.4-alpine3.23-fips-dev

Index digest:

sha256:2d66e1631f2b69a4009495277c75ac00027e9064c1d711acaf3eec2d5d7b5eb8

Manifest digest:

sha256:648a45eaaeee1bcbc3af2b187d0c1a77a296c3b78bd12fdf8478d5cdccd7274e

Size

12.82 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:640c293cb07e2514a3f73547672e218f1e11f39245f0ccdb246ce8512d367391
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:780695459655f8f81369fd674ae4bd6531b22422d51babd075ae1a4327febf9a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oras@sha256:1e6ef254a4bfbe918c7bf2afeab26dc3f4d7232566f2b6f8dd32d43f8f10b0eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:ae4ffec9dc45dc7a4122ac6fe07406080367dfd8df0d378bd14721b56c9b406e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oras@sha256:d5ac87f243dd38c40fc1e5bda5fd552d8e6abb734813284f6cff9b040853b4d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:dbeba70a36b2ea78e93855f37d46df6ca95c102aa9a8fcf1964f962ef74506e4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:f7b64eba57267492182f288f8dc97183f33f8de69898b114714587ce7b12543b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:b9ea722fa09fcc752f36e6d39cca80547e47bf12f64517b5a1bc52c027da6859
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:539fb1a393a0068c2fbdd88166fb263d40f7b4dd59fe1f2f7fd3f32dbb98aead
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:a0f9d86da19d1a08c409b750b61c95644895631a4e0d12ea4b1656fb3dba359a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:0de6bd89dcd56bfe66b5aebd86f290be155851e641ff7b49048bc8de84794566
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:a7e69fe33b171d0a6fe80f62f8671d08c44c10fd94dedfe1cb39603ea13f4747
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:2869293f2cf51ddae80e5e07e75af89808e02aaad72c61cc7d033871fdc2cd4a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:bdf54eace3cac53a48c521499ec6ef61c5fb1359cd5a07976cdc1b65480514b3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:cf5f2292c67170402c2503214ec70691818a7323a9d46d2f2ca73f8c91799580
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:b17776a06b50e4d9cbd28eea0004592a7c799b1f0c4558ee7202459ba3a66123
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:92edacf13e35d66fc150f0e7672af319bbc3afbf94a58665c517f5efd5295133