Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.51-alpine-fips-dev, 1.51-alpine3.24-fips-dev, 1.51.1-alpine-fips-dev, 1.51.1-alpine3.24-fips-dev

Index digest:

sha256:9f1f849c4a999d13a335e589148d2c7f400b97c6a03b4f501f8d7f6b18566a96

Manifest digest:

sha256:ce28cd6e5382ffc2f9c5cc14d1b565302d49ba1c0f73a8e3ad88d091606db160

Size

52.13 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:6ce8f2d9d855cb1535c2da9b31c2e42fecb86150a3699a97cf9555bb5b226a1d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:55cd56857a45c251de733bffcabb09ec93b5c47e22c873d95e495101066b5cd7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:0366de0527c5d2e7a6e1b67e71560030502688ef855f76bda99e1441b6b20d49
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:d89c10be07da8e7b568cf194a6f86ed9c40c25c06868da9a437d4433101037e7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:7411b874175260640e291d447b878e49602fc2ec63a1262ffad18b97cecf8f34
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:696e3b351239fd5b64c5405a8566c889dba6b03eff433349a7d8837095f7be15
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:3617fc44a1a50377384cc49a41dc622423b4c536f2a91e8b5241ebb578a0bcdc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:decac1eeccbead06db7f4850efffaed2b6c61964ad400e2acb68f577eef1d03c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:ab43a470ccdcce1afdb8811c1a9f217735fe26c448203a8a87678248bc623b7f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:ee464ff019fd7edf65f8179065c5d729dc03deedefa639e4ba36545d8674160c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:bfe1ae2c96ed35088aef62c4e6ef3861cc172f10d25728511b86e13f9da9b6c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:d646c5a884a31cbad7a5b6f4a260319041c3c81277577e623c6bad848155aeea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:8bf1094eec1d973b1e2829ee57da95e7bf843640fb36642959476943e7e65d44
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:2dce4f4313d35edcbb866d3c54b51007c0f1ceccf93a95ded49ee7e532e11d62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:32628b5ad6684cd17ccb68cc51797729989aa5ba21847c9847edca0c8b9f99ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:a4a7e7a0865998ca7192099d9d57af6d1d857142579c1ca6fed23f2e2bece38e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:e49361e2e3bb6d6f3e837757618ad1365a8624d59c59a02b04c9b4856f0a9ad7