dhi.io/snyk
1, 1-debian, 1-debian13, 1.1307, 1.1307-debian, 1.1307-debian13, 1.1307.2, 1.1307.2-debian, 1.1307.2-debian13
sha256:9b85a77dc08ba373a3e2d1c940b21c876c20e5e6423607131dea1da9c3dac388
Manifest digest:sha256:59c87a420bce4fb0b988995860a03509118adfde576f5f3664a2825dfa7ec1ee
Size
73.82 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/snyk:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/snyk:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/snyk@sha256:7c17fe7d53f399eafd4cc277fc3291547c2e27b908b823bcb8c13e53f1820837 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/snyk@sha256:f81cb84225d6a3afb6f1faad37d6c6ec2fc4bb41cf208a55213a0d2973f3a749 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/snyk@sha256:2da0389059912f36962a477cff1c4551815f0a4eb7bf02fd5fe698c4616671da |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/snyk@sha256:525ae1b127946919117161d07910deb457e43baac48ae08727d04484421b6b85 |
| MCP server.json v1 | https://modelcontextprotocol.io/server.json/v1 | dhi.io/snyk@sha256:cbfa79bc5b12fa93023c809d2fc626311321911b6a016042b6de70cccc70712b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/snyk@sha256:9628e0ec06728f575c35233ab98bdbcdb7f4a175f45551ea89744a89e1678754 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/snyk@sha256:fe34f97d09e5c4538ee67d14c5506de3e1f0eec06215af6dc21e0c4faa25746a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/snyk@sha256:a4143fec80ec501695a9ae84091272e5653867c2f46e1648b4851f4a0388fda0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/snyk@sha256:a5ee0877e027a080da371a88d1f56ba52db1ba58adb6e51c18051323a3f72925 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/snyk@sha256:8bfa67f6451847e675d8f25991f82c16c6fec7180a6b42c796bf69a416642c9e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/snyk@sha256:47bafecaa5df8514ad325abdcea8f13902baa6257292116959a93c45d3b0832b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/snyk@sha256:c849997497c7cafdb836a01f1a285ed6da13dca115be038019137ac01467a421 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/snyk@sha256:b29c052bf6b180c21005d2871feb22c786459170da523b30a55f66df84bbab00 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/snyk@sha256:6cd7d94d35121c2d36a44c4acc9ea68391f7127a2a84c315b34a756f62f92518 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/snyk@sha256:383e82e3227e2b089b8e8c3a8ebc97e245ed2d430a382e321c69db2a2611d51d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/snyk@sha256:d1cf5798c24ba4dccb420ba214c81ee06676537c8892a97a643ecb8b073c04d6 |