dhi.io/snyk
1, 1-debian, 1-debian13, 1.1307, 1.1307-debian, 1.1307-debian13, 1.1307.2, 1.1307.2-debian, 1.1307.2-debian13
sha256:138ba6e90db4256a67377a4717fdcda3a3ecd2e349ff92b13b0993375e867dc1
Manifest digest:sha256:110a3f05e7c406c3a5513733f840e267b29c6000e43c8c554c4f871df44af0ef
Size
73.82 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/snyk:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/snyk:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/snyk@sha256:adf0b01faf3d3756c181bd75740666263f15aefcb1f4f7cf234f375e9f71a5af |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/snyk@sha256:721eda2418035d515141e5d148806c2916a9b176f768c7782a40f1dd9877b5f3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/snyk@sha256:0742749e149eef72627e4f989c3131bce3055e982934382e659e87a8f83e0f12 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/snyk@sha256:9ad4a2f2a0583250f61cefb6177f25df3a7c0a4706774a611d8caecb7f01f9e7 |
| MCP server.json v1 | https://modelcontextprotocol.io/server.json/v1 | dhi.io/snyk@sha256:45dfd95d1f54f07d5f16171208bd01a336cf56d04ea978b12deb096646bf3c2a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/snyk@sha256:e8b8ea0885ac0e6efc25633d3b1695757ad2af1e475dc1e59e3aecdbe7121184 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/snyk@sha256:1d9117615b323531153893188ffc95026587403d05602269507fad11639a2b39 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/snyk@sha256:dc22a4720e5a717f58ab079a0f6a947d2ceca40e77c9da14f833611c01c3ecde |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/snyk@sha256:76e6535a4b85a81270784d25a4976c81db0b9ba2c5779eaec9ed711375d56a16 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/snyk@sha256:9327a2861f3b0cc9780b021332eeab414dc74a553375862f908dddb80d33c1a5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/snyk@sha256:bef23da9c25082da1f8067687d1d4178375d0ac1fa4b9b77bc93dc472cc7cf52 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/snyk@sha256:eafc3c48022f9d90140596137d7184acb299dcd850b373b64f03fab5fbfcf3f0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/snyk@sha256:a5ddc07b88bf32263797046f9c9db71528c5e5d0d2847e267f79ec6c1028d2ba |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/snyk@sha256:8d6039d13ebb2ea04dfb402d791c782daf17905bcdd6f68808c2eaa6328fadad |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/snyk@sha256:437afe5de0dbce54a68301d26df462153fbf28df1dc7f22f296c6eee649163db |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/snyk@sha256:7ed4bdd9c10334a809ad0a029576bbd254e002ff7e664fb2679380c2319db2b0 |