Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips, 1.54-alpine3.23-fips, 1.54.0-alpine3.23-fips

Index digest:

sha256:eff50ed472b54f92caaba823c0c43e0008e36a61c99ae0e9e37c2ce0c6a43ce5

Manifest digest:

sha256:4955dd97ca562eb2d7b3b51ab6e87f9b46133b3934748a5702d4ccbb4da4f012

Size

29.02 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:f62ace6cece82a27c8d0f416e091df37bf9777e6c043a5f5b3e9382ce66664af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:6be653d4b963f369d2792e476b5c856209b61616175e606b965a7a96fcae9f74
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:5dfaf6d4dd43e31969b68a67bd18be4c70d50d212c0339b835cd7c9d2cc69920
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:a83eb39f10611e6f46b6f6228c57ee15988b88f82d9cd954105331355c89f12c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:770e7cd8051edef6871849eadf48b4c2850d09945d15a988c24ba18564ad75f3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:9170a1de3bfbf56067d65df10a2dc3d2404f412cae8539b9b74a22bf57fc0abb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:33f9f9c86720da54656e352495779e9dff6ceae62553ff2e13956e07c3421884
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:9fac409a7413a1176e2f78db83980aef3177cb65085641bf511ecef3a047e4ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:2df1544a7192963c47420454e4da229e586f8359f2c4bcbb514de31b399d6669
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:32c59bca8b1530ff3da74a3232945f63b235ce11859a180eda0330b85c3f76e7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:a072d04415b5104f492ede54c12521dae59303668b3db1e35e6329ca0d56c04f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:7cae638cca10f94cca2901d3f0003de463dce62677e64223f808ec2188295e5e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:b02b6223d76b0dc7e299a632d80ff58d96527f4ae13717d10547065942f7baab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:a730316b46d2f22af95bfe470e6f76c79c20406ae9ad059cd5ca1b17c25cb389
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:cd0310923d3c76433bce009fb3af518a199157d48bca18057d3688f6407ad485
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:0dfea07ce16a1de5faa73cb77f4365810104e45f70aa1ef87d82f5f352f73872
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:0fc91d176335dc8d0258131ed51eeb0b81fe67c558a55a619fda8291ce34cadf