Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.54-debian-fips-dev, 1.54-debian13-fips-dev, 1.54-fips-dev, 1.54.1-debian-fips-dev, 1.54.1-debian13-fips-dev, 1.54.1-fips-dev

Index digest:

sha256:3fb6aae49b77005156d1e90731a1e56a2836625855fbb48da1ad8d107e9d38d5

Manifest digest:

sha256:93bebfc9bee748ecce6155f474c3c46bfced0299fc533bffc5a0905776cd0b95

Size

71.46 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:f4f1293370e5f4ec06debd39091e196a3d1063a575cbb5b025d90596489ba7cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:8468c4fb6edb80f6a564c3bfed7582ace511373b829b6bf49c566048ea8dba1d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:82e5645cb921f15a17bc7cf849bfc192756fd6f7f8d08fbb665b563fd681969e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:6e10a2b0a8d91ec053e0ea6244e7755b8670315d457fffe5a2e498e9de303d60
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:2264c14d8af52251f9ba2a1ce738607ff967f8af9e4234d0e6f5128b83f6d9a5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:8166d1730954b95c7ce24e18039cf3a9dd2351a0f8c0dfa34c1cd749d70a175b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:3d62d5cae9d0926845a698f946711bcc02bd600919928a9cb9a8c4af8bebe4c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:3e224aaff26c2d5211c95cd04829dc89d7fe5e8d2478f7921161aa609502657d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:ce1a9fd9ae80ae5c744155483ec0f1a3b8f911e9beac3bf02281ed946ada9a72
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:4f0f7b826141f67d276a2eae5fcb5413b38c5da28c316e7411474721ae0d054b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:cd203be067e131da21b89ed39048684af6f7b7c7fa00763675b02eb8f1bffb9a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:d127dcbc2bf8fb2fd479120c10b1f9ed1472546d295fb0a7090c8a8d3ae91ba8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:fd2f19f82713fe8efabb064aaf095f2f78d389ac3b6e57b534dfb4a8b966f154
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:bc78789ee132c75bab08aa9283458b1bda5a59082eb5ba8e968150a732f18648
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:00535d75b44561ea8a6d73dce7ddcc0bbd059ce24f85d0eb53ae18d94354511b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:2653240584b021ee534c433fed352e823db3e05d49db6f20f906ec5e79ff91fb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:44b42c418709079f46c6c941ebe6fe474582ba9c03db473051ea1388f718aaa1