Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.54-alpine-fips, 1.54-alpine3.24-fips, 1.54.1-alpine-fips, 1.54.1-alpine3.24-fips

Index digest:

sha256:4ecc159c6ff608369f796dc7c8a7918bd1c9ae095e210a125a8b127e19c4512a

Manifest digest:

sha256:e3441c779d88b7a898f69f05c8286d15c5943a46867f868e8058b17fd7e8ff6f

Size

29.02 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:c7c3ea7cab873584a4d63bc8dac504e20a239ea5bf243d188c9a677a4037de8e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:6ff7736c3d1472d9805c4e0ed788ee8e9c7d09f9d99c16b35a0341edb5db7ee2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:ab4dc41c7378e6ee7d73703a1b7d0ed59dae3c57a364686deee1c96f0e58adec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:725d91f5f2440834cc6bbc277033f74da640a304ffa9e41b8ba7779ec46ed32a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:1a5ef8c6dc3ce2c29bdf8ee86ad3143467e8d1fce802403e9d02da598abc1eb2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:146666f6bbc388ffa0ca7e5d058117fea286f443d7983803bfb88abdf5bf97cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:43a600064e4874bd3903a5a24aee43108c6b94430694d7e6e4ff8c39d79e2815
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:ff1e4ddaecc510bb5d1fe0b011e962e4d7c424039379668963ee6753fbd5fb1a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:d3c157bfbb3ff02c3c3d26482d202c104e8ea329b50b9cd1839d0e803054d364
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:cb66ffcf3ea5e33be7c63f294afd22b467ca626d0243f00ea239a032ab7385ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:df15aec196bdeac76cd2cdacfdf057d187e937900c29a2800c3669c11e714f0b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:d26db9b8f4e29cb508a1a6ece7cb0a30135479706704fb362c0f82860e6ec0e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:ce9ed22f77e1adaffd9133db78d497ce94caf68c1cadcfc334d80ee53715a894
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:6e34d717d1bb0ac6f175c1f6dc358bf35cab730c2ad9109d228c89bddb5aea15
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:6e30c98b0618873a2bac95ca6166326d4a952f7765cac1673f5526b7f476cad7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:6bbebe93005010a355d9ebd77ac9b5fb9ffe0eec36ac84d133c60ec1c97da0c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:eb515fe137a9fbad8d0d2f5862c72b94046b5a544557e3fcdef3e8975c74fded