Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.1307-alpine, 1.1307-alpine3.24, 1.1307.4-alpine, 1.1307.4-alpine3.24

Index digest:

sha256:ab1b96dab4a2a5681d83da94f37faba68ca6c19fec76d6e3d12f6a8073520877

Manifest digest:

sha256:9936ff739acd1ee68ee16ae1ee7e6013d16aadc3449659bdbd8c84fd796e41b4

Size

69.76 MB

Last pushed

12 days ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:cfbd638eda266403a641ce5b49a71279a2a277736eb74e64e78d3fa7b14b99ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:ed317620ad734cf666aaf48d35b12464c8961e150f84aa4650ff86efc6dc3fa5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:f832c0d897e914fcf9a927f4f8a8f20d4fd7aa6a41c3f2cc0bd141dc86d118e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:aa9d9705fba35a4c58e1e3f0e518a2787552960728189551f742310d9ead5feb
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:e3b536bfc30549c1a55437a1f32509f05f32fc65f53b077bb19b9c61e87e1a7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:5f7a2a5c1ca75546ae7cada2b791153a78eb08cac3fba96edbf43366d6e3f0e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:a0af2dad35fedaba7fbd3e5ed026b16743727e7a7b9291df78359ace2123b566
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:9a9562e3fd86011f54b855610b1e20da026968420eda564c0ee12f924950b78e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:656ce2fef991540f9f64939c6045085aed1dbec66074fc4334a4ccb9fa75c5e2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:b474e0d552f92acb7ccde908977044444b57441d6caa6d5ca507c5928a5e5a95
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:618c6f5ce6fc79c80c9a940204f475c8cc76b055732916586d71379c0170a8c5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:9dfb23c87ada3a7997c6163bfeaa1fe23fde3dbec5fa62c5435ad8da1c329efc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:ada15e842d9a79b02210be29f04f3ee4bf942504fb8e99bf040df01d5af39244
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:cd69faba5545d4bbbe67b26c8d2db8f0c008784c59309886e7666194e4b78d4a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:b0846817e1e1d975170ae55a0cee0307b4094580d8009c9cc4090735a22c43f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:d08d5231a1543c4115ef9292fd8a86bd608965135d3e4b9cdb07b3828bfcc88c