dhi.io/syft
1-debian-fips, 1-debian13-fips, 1-fips, 1.54-debian-fips, 1.54-debian13-fips, 1.54-fips, 1.54.1-debian-fips, 1.54.1-debian13-fips, 1.54.1-fips
sha256:6fe248549238233c10e88665d4d0a85fa2229055e45690431d5b835be996c4fd
Manifest digest:sha256:a9e50eda49030a3494a144a5a17ea0dc209b1e6102482c54ebc92d330f97852e
Size
34.06 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/syft:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/syft:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/syft@sha256:a7477165b96f068003d6ac751fb381a4aa02d65971fe75b8127cc6ef39cc32ed |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/syft@sha256:344a1f09cf583ab591200087186600722346496eecb63f629ad74fcd4258168b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/syft@sha256:f0333a1e184d993c175498417781b3deb62cdee88aee6a256026ea2a56055c5b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/syft@sha256:b017db8d7c8f71747aee2f5c4d04a8c27d3b8fc080234596e5660d7bfc2f74e3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/syft@sha256:08b401043207fddbff5ea2714b34b374119a1d5571faab38d996cc8f761b7889 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/syft@sha256:08b537cc61935c567a5dfac558cee2a8b759e58ac74f3b97357d52c5ff0f241a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/syft@sha256:fa8ec615ed576d95dc1f6c37a982d9fb6e651f9ebc513dd825e13eb3197f10ec |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/syft@sha256:bcee5ce4f3203c5602305ad796b3485fc2080c1eafd7e764486b97c6628664d3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/syft@sha256:3fe90b8a51ab2851524ba2440cfbb5cb7c7f91c2672993c9fd6020fbf960fd72 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/syft@sha256:6b5a80334bb0ba61548bc06b6129fcba07c126c23ea84fb0e02ccd29322b03f0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/syft@sha256:02734ee24e6fc48976f40dcbd49bc5b21aae2a5c7e2fff6729b1571f2046fb93 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/syft@sha256:c4e390cebafa33e8c89904a61508e7c468036154b58f8cbbdebdd3f2ab32f4cb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/syft@sha256:6037a8516bc7caed5e9c10ecd64cb7f0af530121ec7b5d73a91fc786e6e0994b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/syft@sha256:32ae8b80671222f9bc09d2dbf2adce964c8bc0752e32ae6ec18c276ecf810cab |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/syft@sha256:1297b5e853deebe6f655bfe9f028248e9f6643841993714672783b751a91397d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/syft@sha256:7bcc76125ee81c2f35019f7adb545132d0866ae5b1386ff85b93fe59065f89cb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/syft@sha256:60dc1397d6c78fc984600bc4e2f47370eee8cba6f7f5be971b6849b5d42fa61d |