Sign inSign up
Syft

dhi.io/syft

Syft 1.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.51-alpine3.23-dev, 1.51.1-alpine3.23-dev

Index digest:

sha256:7fd9f690b0f8ff59fc1b0139c01e44059da79050495ebeba7249d768fa440532

Manifest digest:

sha256:c7300fac94f2f5e695e28e6d769da7f4439cfae86d619460347cb6c50020cfc7

Size

51.28 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:927fb00b25b64a20f624d225743ca473181bd2d938057db2dcddb138b17c0a5e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:75a16ccb36bce489ed097c136c2a9ff80a7810645ef396048ac331da8b48b92f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:93b029ab853c7fe2c9141348cc605802ddd988e9f9058488d122b330706b4198
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:4cc50e3715d46b20423e22f86dc443f635080131a6df423a15fc1475a651e73d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:3ed27c5d40fb512e44f3015d516da653aadc86e1cf6f5b6e18db8958e02aff1d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:39a260da54480d3b5a396f0bf9bbe50c249ff06d760b88730b35ff925b7a9b5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:15c3a43300836f70bccb73e807794b41b4419886896c3a323d9afdf54424bc98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:649fd7f1a6343d7a79964eab4339aec18e909c49082cd609596cda6742ac5761
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:94d122ba2e29eb725df1e49a4f8b4673b7a47f976afbc30d2db9223fd923c7bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:7bec24df8e41e46bfe5030b2d211e1a6b2f2dc5b02f95b28c8dde29de7b00861
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:2d98090879b3bf32ebb1294cf954107bf2701f8b96cba13a639e17170621b4d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:13f5fab6dfe674bed058e919b568fa01241a862259ce77c6bbb1f0242fe0cbe7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:7ff853fa27f8db2af1d386423c430c6d1809db5fbbf2a52a88ae15b4effede2d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:99e6051da84277a7ea9a5a1b4aaac047f495d0cd1f5f49c39d6004178cfea647
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:72e7301c522d28f4794c801b1e41a4246be3dd0ff468c57f0864545cf6ebe36e