Sign inSign up
Syft

dhi.io/syft

Syft 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.51-debian-dev, 1.51-debian13-dev, 1.51-dev, 1.51.1-debian-dev, 1.51.1-debian13-dev, 1.51.1-dev

Index digest:

sha256:2a11cf66039382b3b773821ab71bf268c90473f2e2573c74dccea5e5fc2bb46e

Manifest digest:

sha256:ef58095b143e78a174f528dabc61f24cefad4722a20e6a82ca3d41fb77497d37

Size

70.69 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:ca7d0d79d90bc9f3f8bf82d49bfaa0a14800a08077f4797a75f072d4e2db5901
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:c103c449acae64c6f3c0a1e8fc15abcca5c76301087b65d1ab76b11211140021
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:18fcf25fe987fba203636eae2869eff695e8982b7814ca47b6717166506b5bb5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:698c14f430ef67e4b4263887b94e421072014a91e1717da86b3b26f5a617d6b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:db8ee23b6b6bfd4d0191772167e1e6d0c2e5ecd36d7707a6da52b56d9be8afb4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:68bc7fc3984c0ba383d8be0e21fd4d5ab689d1cfdff33cf48786419ed8609d34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:b3bd1fb28015c2163e8112a649c1f09b683cbc4711999d373950a0170e8be7e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:e5cf2e1716da7ff436e096cf82b5d4576d50fb5d5c8214b5462b781741a61371
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:549e32df751bcaabd988d92391ee45c7f6a33bbe863357de4ba42c49b9f94f11
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:8b4994452e8fa58151d39e9115687ee76945d4024298e74f7613ed19cd2e8a56
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:4fb6969fea5fdc721a73769ef89aa378a8cf4bbe94a0ae3260d3d19e24761533
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:ba9d0ac1a67df210cbac2539bc601af450b4c5c939707d3c1daee37cbb5d7afc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:c47eec8b11fb55837c86bfcc197387cf5b102c823b71315fdcc91b784f462d2d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:d65e044f14d204a6879362b8bd3a5bed7ef25684d22a9597b2344d77224ceefc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:d7d902fe809b34ca57b06f538c1b6578e3a0c3ee998bc3eb002440b99a05e0b8