Sign inSign up
Syft

dhi.io/syft

Syft 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.54-debian-fips, 1.54-debian13-fips, 1.54-fips, 1.54.1-debian-fips, 1.54.1-debian13-fips, 1.54.1-fips

Index digest:

sha256:6fe248549238233c10e88665d4d0a85fa2229055e45690431d5b835be996c4fd

Manifest digest:

sha256:a9e50eda49030a3494a144a5a17ea0dc209b1e6102482c54ebc92d330f97852e

Size

34.06 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:a7477165b96f068003d6ac751fb381a4aa02d65971fe75b8127cc6ef39cc32ed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:344a1f09cf583ab591200087186600722346496eecb63f629ad74fcd4258168b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/syft@sha256:f0333a1e184d993c175498417781b3deb62cdee88aee6a256026ea2a56055c5b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:b017db8d7c8f71747aee2f5c4d04a8c27d3b8fc080234596e5660d7bfc2f74e3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/syft@sha256:08b401043207fddbff5ea2714b34b374119a1d5571faab38d996cc8f761b7889
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:08b537cc61935c567a5dfac558cee2a8b759e58ac74f3b97357d52c5ff0f241a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:fa8ec615ed576d95dc1f6c37a982d9fb6e651f9ebc513dd825e13eb3197f10ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:bcee5ce4f3203c5602305ad796b3485fc2080c1eafd7e764486b97c6628664d3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:3fe90b8a51ab2851524ba2440cfbb5cb7c7f91c2672993c9fd6020fbf960fd72
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:6b5a80334bb0ba61548bc06b6129fcba07c126c23ea84fb0e02ccd29322b03f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:02734ee24e6fc48976f40dcbd49bc5b21aae2a5c7e2fff6729b1571f2046fb93
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:c4e390cebafa33e8c89904a61508e7c468036154b58f8cbbdebdd3f2ab32f4cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:6037a8516bc7caed5e9c10ecd64cb7f0af530121ec7b5d73a91fc786e6e0994b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:32ae8b80671222f9bc09d2dbf2adce964c8bc0752e32ae6ec18c276ecf810cab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:1297b5e853deebe6f655bfe9f028248e9f6643841993714672783b751a91397d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:7bcc76125ee81c2f35019f7adb545132d0866ae5b1386ff85b93fe59065f89cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:60dc1397d6c78fc984600bc4e2f47370eee8cba6f7f5be971b6849b5d42fa61d