Sign inSign up
StackHawk MCP Server

dhi.io/stackhawk-mcp

StackHawk MCP Server 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.2-alpine, 1.2-alpine3.24, 1.2.4-alpine, 1.2.4-alpine3.24

Index digest:

sha256:4a2471de2614633d0f1b362fc7c7fd33bff80dba59e27a561dfbf37e2c7bbc06

Manifest digest:

sha256:172e7c4335f9484dad0160046cc8d871db0adf475efe66a50372b238c580aa09

Size

25.89 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/stackhawk-mcp:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/stackhawk-mcp:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/stackhawk-mcp@sha256:77e27cdfabcd309f5841721d6f1eb90f2c6633a7fa65671889ada28c27f35081
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/stackhawk-mcp@sha256:a298c41d2ca45dddc367c1d866073906c71d08ba8128f1ed58307c5deac3b547
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/stackhawk-mcp@sha256:0b9adbba194daefd8c696e3320f7e5353fd461ddc9cad5f2b19a51e9057c870d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/stackhawk-mcp@sha256:4943f95e9af32cab261e97c80ffccf7b018b8d78b16fd406f6328c974634f80c
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/stackhawk-mcp@sha256:89a0368b92d3340cbcdc48464f801c0e6aa4c4414c388f682397241c4ee345ee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/stackhawk-mcp@sha256:c2dbe15ae1f4416efbb8be6ee148ca7f3fe6b1a5db7225f83680bb0a5e2ec992
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/stackhawk-mcp@sha256:e79ca572979d5fd39f165ad8d51630a2dd38fb59d1d9746a217a3171de32e315
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/stackhawk-mcp@sha256:83f5d42a5dca34734a65edd928ea97b30c96cbba68dc8f26c5dbc50f18ec27f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/stackhawk-mcp@sha256:c0b16f78bb5ebb2fef207d1017c76979f681bd877821a9752bf6599ace8983e8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/stackhawk-mcp@sha256:7fac4768850808cd2fbb1d2955f875e72d5c3d56c06f241471e6e47f6611d4e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/stackhawk-mcp@sha256:c5c551e43efa7f2eb3ee3e07292d4bf2a1b244567d2f04143c5583badf012ab4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/stackhawk-mcp@sha256:f9d2af92a4e45f4503100adca977beb778575ee5c3ad45ae99ff91ece63e9bbf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/stackhawk-mcp@sha256:ba1431d007af392ef68af299bb9c135d7b16656082bd5910d7893ae3f4303637
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/stackhawk-mcp@sha256:b6a7f5193bfed384b008aa9656460b37f2701250a1d2767826921418991fd5eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/stackhawk-mcp@sha256:46c6f937329c157238180c57c14e3408acf2782011849f496ab3301b26aad15b