Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.54-alpine3.23-fips-dev, 1.54.0-alpine3.23-fips-dev

Index digest:

sha256:5fcba86ed67adf75dfe0f9acaeba449f2b1c921262fd9fb4f4cdc560ee35764a

Manifest digest:

sha256:293c9857ef95b6191b091b184e4a3cdb9d4476267db6ec71c47119b9986722cf

Size

52.09 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:d1bad694fcaca5a8e0488ca740c29e7cff4d0aeefc1b41b08ea0ff7181b172c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:72156854558bd114c761bcb8f8df8f600ed06426fb2b14bbf6fe13e547c284f0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:42050aa1e8655bd4a668611f871aafa3fcca823e27553929067c6a4244b71b71
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:0d255d9d22ab69052247e3ed4e21158ceb91adc559b9b9a458d1af0e0a70569c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:be2d002c0e28d90f36d55c3e124f77510ee31db4681fdbe4af79a0a2bf48538a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:fbf89c96b193ae8906ceeb38f778c8d78448a1315f5c67e252790e40bdca0244
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:ba83211a00230bf5f3c969fe96d42f0ddd6357887c7644a7a527357cef0faf79
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:f2a33a58118bb1dc8183992c29257f9deaf8ad53b08466b6388755c54d5e7faf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:7e74a921fe04136bd49596633928c4873ae2610e418b7a6c4ed8dc1095bf44f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:8e09df02b56bf3d11d1897a3f3565746e44876bf40de0dc62ad2b103f9a74e6b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:fafef57a911ab3cfaa8bcc3cdb1c30982517003de5e1d2d7bd81670299840f3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:fdda67e43277a183d086f52c7a19cbc89bd465eca6755f41ef36e616f62d4c09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:34afeeea965799bc8b152cb67b3cf5213dcc7043b75a57ac5a2d50e482584cdc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:e4fe492516b406b5e8cb7b72be2bb9a280a6b0739510141d16843f836be1b787
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:9a4d37660bf396b23d9449e6f8321b8d8f5a7c74443a4b99ed8f56b847f57264
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:d4a4e936fdb31f051b3cff94c7bfb547840d2758a341a89b26c5e991a26c426e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:648d2461c49e8945b00a3e743f6f14d30cd834aac067809af33417a050932a5e