Sign inSign up
Snyk CLI

dhi.io/snyk

Snyk 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.1308-debian-fips, 1.1308-debian13-fips, 1.1308-fips, 1.1308.0-debian-fips, 1.1308.0-debian13-fips, 1.1308.0-fips

Index digest:

sha256:2e78813d8db4907ed92454ede9c472418505162f59700cf890a41f621ba0cb13

Manifest digest:

sha256:9e73a2ed547239273d5157a77e47d6330cecce8add3e1b8a7c9fc3c617012f77

Size

75.02 MB

Last pushed

1 day ago

Vulnerabilities

2
9
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snyk:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snyk:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snyk@sha256:458cb6741a0a6fe300553804b6e9804f1d620815e880cb8c49c6697432acf3f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snyk@sha256:e79b50d81af195a3270be3089825c5095a4a32ca0a839e1a303fd7d3c241a776
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/snyk@sha256:c0842e2680347d498312b56bae8270dd62363395728d8beb1f3c62debc13b02a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snyk@sha256:728a151c2ac517b446b050602d91401d498538ed80d3085385939830612fd468
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/snyk@sha256:379beca439035bff10b2547a5e666d28cbb0ce86de3e72f9335db8d5aeb09e17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snyk@sha256:a2f700e0a693db1dfceba72e5db3c192ac829a45e8d45ad4685bcc7a73986195
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/snyk@sha256:6f80c9bd027cf7bb46017ca4a3bd1c28003744b6160c1f29b1a913274eeef128
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snyk@sha256:16e0422b1a9822d0c3d77911ff83b66621c5646b5fcae4b3763e9aa542f33f73
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snyk@sha256:3affe0062d9d320ebc6472db1ebfd0bb0c12a971115fd933b60b5c21fcef0cdb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snyk@sha256:ca7c4a94b66ea597924e37973cec27f1047594c697d1641016fe9cb4f747dbf5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snyk@sha256:9ecd08ee3891d1f54eec848ed512e27bdf0f43655a990cbea6ace2d1f8e5bc1c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snyk@sha256:8834883d1538db989bd9a8ce05bea36abc24f5f0dc0fe9b3afe2a723f0313c89
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snyk@sha256:595045c97baaedf16e6c930ba22448ccc0c05be13ea7bd69d00889494aa00594
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snyk@sha256:cfca58fb5fa26eb315386731acea81863e47ceb76a431c57bd291c20986f0873
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snyk@sha256:349aad3ad56854e3112ebc5c35abd2b2606c7032a04cf0976d2639313f715774
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snyk@sha256:9cab9f941a150c51e8409cbf307566c4f48f2f1a41c59bc4f3c5818a1d3c22c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snyk@sha256:54e80b54580f0a370060ee042ce8c328a8bf9625533d314bfb547950f33df320
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snyk@sha256:a832f9deb004d9e6978f24f0ddd95a27a3a4613e4ffe5433cbcceb2625d64d82