dhi.io/syft
1-alpine, 1-alpine3.24, 1.54-alpine, 1.54-alpine3.24, 1.54.1-alpine, 1.54.1-alpine3.24
sha256:47668ede4bed497f7b34b05000bcecc23c677f789238d0b0c84abe2533959121
Manifest digest:sha256:408fc5be04949d090d6c320f1ce9fdbebf6a0cfe78ee33cf2efca589795b5f93
Size
25.60 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/syft:1-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/syft:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/syft@sha256:2995a7e5c821f1b90db442647dcef5275373ac2597645a980c2e3478c47deb06 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/syft@sha256:e710d0892980c0423c783cacae31c614b5568ad1b359f3db70348936edf17bd6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/syft@sha256:c28e93abe91af6c158f50bd1d8ef99e5c34b06f213c19cb66781c82e8608e7a8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/syft@sha256:6fc03ebe91ac1884b9f13427cc222538684684353b85c6464e3a3184b2d416d8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/syft@sha256:be1d229f64df85fb8cefc2fdf89c62c14f8c41ba0baedf8c409f0d2c3dbb79b1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/syft@sha256:1b05418a86cc6ab29d29c4471abdaf6b9c570196ed24bfe344c9d9d4237a9473 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/syft@sha256:80a669642648a87b2ab4f437afb3831aa134082eecdddb4fd5169e922f444dc5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/syft@sha256:aae33d91ddc15fed663a69ea61071a60330ca68b0d067c9bea765ba00640e62d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/syft@sha256:cd1db55283dba704daf062bd4e47209fdfe1263193ab561eabc3e10f61b99f37 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/syft@sha256:0eeb07c93489c27bedd91bc7a94dbffc427c12204b4dd01db0c010b810ae7905 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/syft@sha256:3a9588722899736e16880a3aac3c41cb821ce63664f3edd574bbb8994160f274 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/syft@sha256:66fa66754c08bd2357d3142eb603ac8095cebd392c7c929fa3f3140520994343 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/syft@sha256:0b1a05956eced4125f053ccc716ff8a122f85b862c4991612ab6e0fa9ae01c90 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/syft@sha256:5fa8d242d410b5fe58984702a22ed734196ee8d003c0378cffc8d0e1c950d615 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/syft@sha256:e181be924a345182182a6bbc7bb5e55ecf8ce4c44885ed28e941984f4138694b |