Sign inSign up
Syft

dhi.io/syft

Syft 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.54, 1.54-debian, 1.54-debian13, 1.54.1, 1.54.1-debian, 1.54.1-debian13

Index digest:

sha256:754efe1eb332c9d9169c7fdedd55bfb0a7b6d5bac9fd86b0488d28b2b580f776

Manifest digest:

sha256:74a800c60e2dc9ea5b121afeabd3c06cae859492fabad3919007d5a00bb574a7

Size

25.89 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/syft:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/syft:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/syft@sha256:6ad419a026cc8cc5781844c3db2388a2fd3533ddf2d9c082f69fdaa4dec6673a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/syft@sha256:48f154dc62de958f69af3add22c8c7817c5871e848b1fc76e86b998e32005b26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/syft@sha256:bc1abf26061753db52764d8082807569ac23732153a7e4e17c4042235332cb83
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/syft@sha256:ad809bfe17945d04e86feb4e6f54e778d9e68a8665eb63f9cfdec6fc30236953
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/syft@sha256:49919f868af4386be59774f040f05f6c01191254e0d61ea166bccddb2d4af853
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/syft@sha256:e07f7477993609f1e4259d458596ec403eef1cf47121807aa75e37ab2726a958
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/syft@sha256:c55395128f7863de4c794013da4ac94c5a8f11fb8f5f8c4e2073e177e2904b6d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/syft@sha256:eab055b0215f937509ac8cb70eae4e4bf2678188c46d9c7e37f2bfdfa2f0b1d1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/syft@sha256:7391112eb0ff46cd631ceeefe43b9c75097a736cf58b3f96df7b434a1c1cc574
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/syft@sha256:c1870ea5a655a00f99c3c58ac7b1f5be56f4b26ed4dd587f227b06197c340d10
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/syft@sha256:b21b3c157cd0946975310575d95455b90461b3414f4213425eb3549628c9a983
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/syft@sha256:d0e04ec83f6b4fecaf1dd0e67564976bfb3884607d2cbf4e2f860ea9f3eb82a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/syft@sha256:8ed85b6631f432faa4a9908b2b59bf9243be0729c279e96d829ad90ddfcc29ea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/syft@sha256:85047c1ccf9cbcba38c30bb3f18d294d5e1008bbd0588c8725a1f1f4b6a6ee02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/syft@sha256:c86b510d7601196360879c3cf0e84f7e5ebd1d4fb00c2e2190d903930ee31469