Sign inSign up
Syft

dhi.io/syft

Syft 1.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.54-alpine3.23-dev, 1.54.1-alpine3.23-dev

Index digest:

sha256:86582594e11292b041b5441e415aa68a65efc564925192feb387309f4e2e31f1

Manifest digest:

sha256:ed339ca5b4fda10fb440e73a2cda26fbd87b4ba20fe3c98f7ebd171514d1863b

Size

51.27 MB

Last pushed

2 days ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:921a856100b574022f7841fc3b86a37eaeb1ed76ab8f94fbed08af615524c1ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:2f7504050123c602b198b2070b402b7efa34bcd7cf6b50088a31ac84040ae110
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:e0ed21494fa4bc1161cbea2fad90f5d4d7464253da17cb163d13bc48812b086e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:4ec4d1531d13df63d7cf1ea5927271291b1b400e14a8640b29ac8a4277d29332
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:6131eb6d6a65c6da38e6f445dd06554e815eda5c62720605ae33ee385ce36956
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:f146bd4fe4b8c2b99449d3c2046d0a72c2961c52fc884efcd802309acb784d9c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:8cf042fd53b71355fc78c652a9310c012ccf2f6ca203d48a3f59f37d1691814e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:6e0c43f9da3814deb8e796ad5a64ce62c5d27e26d9f0fc619e7ada86ad0a8bbb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:822da0f419c171909fd9e99c871ebecbdda12afdc4692f345fb955e037d2d89c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:7d0fb02bfe18a6d268ff81b38ad1252a50575564d5a8f4a02a6f6fc17fb9d3fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:11843a037d6bfad3f6d9adfcfa7fdd4566b959b1496fe57a9660068e512fdc80
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:31a86f20c5f8da7dd14cd1db629eff3455df23bf13d01250906d702a509c4922
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:903f2b18c77d822927a8fa74e723ed4aef426737b2a20e8543cffd4d563361d7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:ee7217e55703f6b6ed66390351e02f38f14c7e54ef3b103ffce12b4413ce0142
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:a7d25bf2112fde9851da129b108504bbb9882d7dbeae38502c868c9194816d7e