Sign inSign up
Static

dhi.io/static

Static (Alpine, with musl)

CIS
linux/amd64
alpine 3.23
Tags:

20260611-musl-alpine3.23

Index digest:

sha256:93286bbb3ba4023e250fdcb09243cbda964ad32a23573d9b98dee41690a2e529

Manifest digest:

sha256:cc593a3d2d5eb0de7b281bcaa901b2adfa53c3ce42a547f2aedd1f0048b864ba

Size

716.80 kB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/static:20260611-musl-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/static:20260611-musl-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/static@sha256:5dd9ebef6bfcb0ac226bcf4d80be9c1cf17d9fe0f4d07fd5eba0a17c8996d003
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/static@sha256:9dd38e7ac07ad90ccf1141c787565eb326a0846e2818b0b0e3c2e01bca662a0d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/static@sha256:ef80a86ee7b7da6e64a85fc224f67a80ef03db376587d745d77423d922576b3d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/static@sha256:13cf04200799e98061355a15b25031b99c8615133064d9efea838e343f45245d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/static@sha256:86dfbdde7568351ce16c9c8f470b742ddf214f5bbcaf9d3454478b0639a09be9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/static@sha256:d5474d50a019ad10719dfcb12a002ed57f150bedb892c206fd77931e3cc63d75
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/static@sha256:2ff96cf2beb3311f168e09626621a3d99243badebea80fa00b61651f1131bdad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/static@sha256:67ab5ca990c17254fa6a1e35bec3ff685d849bf297587e7e73d43936dac76c5f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/static@sha256:ef2f40b2d32f63f74ea0fcfdee2f4651b53ed4ccf71efa13b40e4a3367103ba4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/static@sha256:c2f608155fb0d2144b5c27e1fd908b96b9ccc5b33960e7494f63d13ba985f91e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/static@sha256:ee0586b9cd776bb418de309960281fa0afe031b841bf05808b082133647dd454
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/static@sha256:c2772f9c129e62bec71d273e67bad04196b81dfd82b4641b10db61e0beab64ab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/static@sha256:2a8b10ae94af4d24397298e9bdce231f8a4e48e73fb9b1561d67517e7f62cc32
SPDX SBOMhttps://spdx.dev/Documentdhi.io/static@sha256:d623dd0288d68705603ce750ceb6274e94b8c9c02b11ad7d2b49c13332a30f52