Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.3-alpine-fips, 1.3-alpine3.24-fips, 1.3.4-alpine-fips, 1.3.4-alpine3.24-fips

Index digest:

sha256:f1f92fdae48d7dffbca00a1056bfc25c7d8a31128f71b583a40068f916b86819

Manifest digest:

sha256:20cd49aa22b41ced9a5e40295823784cb881aad5c19bbccd8d8529aefad14f8a

Size

7.97 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:4cbf53b70148204289cd9bd6173fcfcf968a3bcd3cb6d783db2dcd92ea5892c1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:231048c1bee27df41777523897d94fcafa083589c27dc1d7711af2423c12c309
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oras@sha256:8c3546418cbafb95b7e784460c5f19cf0d03d8f855389777c43ae430d2162f62
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:99214badb879064165aa09ea31f0d21822601a514d1cc3c5d6da056dc4702e5d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oras@sha256:cf9846b0f8963a1b7c0fbb89970b39269fe83ac3ad296d8ba700c9d3626527c9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:877d83d660240968c434658f6ff3470632b37b53520a8e84985a7941438b0e49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:5c6cb0f84e6d3b236dd787d9365704f7b10b338ac44a9b18dbeb172f35a08f8e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:6ef85be08af35ae3b15caa827c67d5a4634b6c3bff19276d2c349a922bed2861
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:fb0b65aada60e42e6b09805c808bfc10a368e38fcf94e188a7c7dca51797c455
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:0ef3c409458d2343f2132f4115adc5d6f2af9cda6ee967ac70da784a88a6a11a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:77267b8b648c1168c023a207cf80f347eba36684f880027652dd8b89ffc35b74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:460dee0c821a9a042ae0eb8843fbf5b3cc406312e7c90e95ff98ec49b9b1d66c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:fc5baf0322c23c62da193eab0fb6d5f05fe310421783d85e851bfe429d84d526
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:1849df651b54a08145c248eaae3800f472fd43c85c5a3ff1acc31338f8031e29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:7706f28e3fc9a550803b46d4e8c4851ac34ac83d4a4f71e4b81633e28bcbb449
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:aec10092645bb13d95f59e082d93f2b1345cb42a535eef9b9a393656793a1b0f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:5efd1d5a66b8e712df5c338e74291a7631468cc15d6ae2843c3f714aaa6fc73e