Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.3-alpine-dev, 1.3-alpine3.24-dev, 1.3.4-alpine-dev, 1.3.4-alpine3.24-dev

Index digest:

sha256:ef43c907c832413335a902434db106a2a81a3e92986ee47b9531aebf36cd47a6

Manifest digest:

sha256:ecb8ddf714e01e4dd653d76e8923080facac7727349de8e27677fbcb05a6145b

Size

11.99 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:66d7364d24da6e2f3a3dae9e13d470ada7841813379adfacfd7d7958ec76a9f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:0f3f6d47213b28c83b35d564ec64eb8c66907362032c6eaaff69080bf3d74a2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:d1696698b9ea63a2a1419fb81b1bfe1fe1b9108d58e8f6eec99e12c63f23ce83
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:4da0697c61def5eca47592409f3e393c5bf105d7ad53553788983202df1cfb84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:987fdcb2046a67f7075d9cb295b0e3d7312fe601a500ce18910bc980877f4a13
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:f8910d6f8d0c8e9505aae4d358ea0a3427ab95a635afc6766c1f124cd2a8084e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:580b377dc44c08955fdf3a8a367fff5e1e1cf31532d56ffefc57ed7051e15087
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:83aa20ba0475e25d23e28d6587004cb46f489861298d15425925b26224a1a1bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:24a18b516bbe13b739fad19de0ac16904cc0ab4ad184da8e09db88533f8863a4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:9cc1f250104deaefc0735117c2ed1d8c5210f088b61f47617b2e1bafd41481cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:071577dbd25ea6a0c9b580c1fd1dbeebf27b2a08f686e4ffa5398f4b17c347ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:508c9d190ee0642b3cca256d8403a99102df73887a1ef9e33d04555dcce96c29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:a64d63ab4e6da02c4c89e8918bb71817c19c992d02276b9372d1a6f4628e098e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:2fd67242633d62312bdb23f58ff3c9af3c913ea0b10fcc323e0137cc6ed3205d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:abc992f5a42b7475cb854d8e8ac3db68329e9ea55817aadc546e0456aa053264