Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.54-alpine-fips-dev, 1.54-alpine3.24-fips-dev, 1.54.1-alpine-fips-dev, 1.54.1-alpine3.24-fips-dev

Index digest:

sha256:4610dae9ac2c9c35a37938492a406de5116f3802031dfb947d1d6ad386ac30a2

Manifest digest:

sha256:d8187ac08e9b52ce7964c92327cd2f12727556237009fa952a9787d1c32da795

Size

52.11 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:ec152356a0131f894503d67e7f631cf107f825d252fc55d12a0d4ef156d48961
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:cc67b8d1a73a6ef7095ba900cda0316fc26646fd809f90731eee638338e9c1e4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:041a7a5d4fd87d0d6c552c5bc13a161b749a805c7f5ce5d83b774a7f52725173
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:4e820485b2e187ab9f2680dc0b9439cd1a2c08555756020a6de506ab0ee4df7d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:27af2180d6d327fc703b8fbd3e041d2b1fd6e1bb5dbba47ae4e7d8c254196d0b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:b6ac7dddd35f94430599a828d316d99a80963fb3995df1892188e86032b766ba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:02e2be9ddafe9814b3e08a71398f19ed1be89388b1e0b4ee0938d45bca22e6d6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:d686e13017a959f87824768fda79926f024a2120b1ef500d093ccf435dd5f758
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:668a9c844bed6f4c38c511448adafd481ae21703be2d0dfdf3457680ebc578aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:cddd2d8512af1c4ecfafc22c5b957871c601c73e52c6534d412bd474b720c1f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:d4f32e696fb4d57008a68eea5b9e605c084d14ac9605d3c8ecab95ad24bb495c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:a4346b64b86605b13d356304f35dd76a505500942aee833d00bc5692ec1b8c60
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:98a9a7b839986fe89236107bc7735ec56e035439df0fc36c8972333f38ace1e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:b258093e4cf77fc499bb239d43f9e965363a81d3a446b5a7438ee9af6b1ea4f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:8a1c35251ea27eb2f4cce3acbc023271dddad8bae972e9e07b47686ad610ea51
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:e2ac373d46d5502fd8dd251f3d67b32c200fa885eecba194042afd32c842785c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:ac4d1524c9723b7b8c6594c247dec01d6e86acfe93531a059a7ba700ae1ca02b