Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.54-alpine-fips-dev, 1.54-alpine3.24-fips-dev, 1.54.1-alpine-fips-dev, 1.54.1-alpine3.24-fips-dev

Index digest:

sha256:12b9f2683e1959ab814d5be697be461e2ac1bc25e751ea6f40f4633e08ab11ca

Manifest digest:

sha256:c0dbe4a97cc0901ef303ed4295e0041edf0d52bec93bfa849e06f95dabe785d6

Size

52.13 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:b94a10bfd0d263227c825921bff18ec4f62292b1e9d71e24ebe3c1b0521dd54e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:430385eb6ce836cec0299601bacb4a8085d6c37b337cd5801eaaf824a1716488
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:2269978d6e4059a3bab6823a917f8d7e9fe1a0e69f000287023df85c21015e88
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:4eabe0bfe25097c6f94eafe263f2a9df6af5b63e4a45f8984a51ffa96da9c788
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:d0dfb48e922621690224eaac8842ad78a29d95c1a053b7e8ffb203ecb0afd702
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:056edda6dc1ff4f750e0b66020ac39272ef0ae1fcb8a57a42334bfe96010b453
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:25d8c8790da3f6434a9bb388aa36c5d95ee08cb2e7054cb4dcd4856b72a0ab7d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:3a7bb102ea7215ea14445496b1ac9df42c2beba888582c8ae6556978c3e2623b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:1fd720da86eb41d4f0e24d20e51725abe0254c96df04d5ec688f0f430808a398
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:204f6fefe2f500ed996c7435e628a629bc75a6b30a2ea13ce5331d0f37f4b8b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:a6b7cbdd32fb372fd4af7317d87fa7c4f106fcdc61cf05aa2c5c82ce6c6ab20e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:e94179cb4daf57ccebde1210ba92057d72b92f953738ac38e7de7e3836187f30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:c856bae98643730f19848be1151bc6b8b086d55d00721d2a1a5c515eff7a86a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:4af1ee96f452c5cb518e6286bcbb14d4ef2dadd76ce3ca610676fcffd20c4dbf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:d54eb29d087d297d8df808fae1573140c050f6ee8437e78c46d75317825aade6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:7df4f754a32c2ba64db5c8dd88cdb2d118384264d1f1a1d7329b4ae4e50c0d72
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:197a4348d20fbc6a8ce4f918f3dab9425aa7bde584088f80dd42ea6803826afb