dhi.io/syft
1, 1-debian, 1-debian13, 1.54, 1.54-debian, 1.54-debian13, 1.54.1, 1.54.1-debian, 1.54.1-debian13
sha256:754efe1eb332c9d9169c7fdedd55bfb0a7b6d5bac9fd86b0488d28b2b580f776
Manifest digest:sha256:74a800c60e2dc9ea5b121afeabd3c06cae859492fabad3919007d5a00bb574a7
Size
25.89 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/syft:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/syft:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/syft@sha256:6ad419a026cc8cc5781844c3db2388a2fd3533ddf2d9c082f69fdaa4dec6673a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/syft@sha256:48f154dc62de958f69af3add22c8c7817c5871e848b1fc76e86b998e32005b26 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/syft@sha256:bc1abf26061753db52764d8082807569ac23732153a7e4e17c4042235332cb83 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/syft@sha256:ad809bfe17945d04e86feb4e6f54e778d9e68a8665eb63f9cfdec6fc30236953 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/syft@sha256:49919f868af4386be59774f040f05f6c01191254e0d61ea166bccddb2d4af853 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/syft@sha256:e07f7477993609f1e4259d458596ec403eef1cf47121807aa75e37ab2726a958 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/syft@sha256:c55395128f7863de4c794013da4ac94c5a8f11fb8f5f8c4e2073e177e2904b6d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/syft@sha256:eab055b0215f937509ac8cb70eae4e4bf2678188c46d9c7e37f2bfdfa2f0b1d1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/syft@sha256:7391112eb0ff46cd631ceeefe43b9c75097a736cf58b3f96df7b434a1c1cc574 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/syft@sha256:c1870ea5a655a00f99c3c58ac7b1f5be56f4b26ed4dd587f227b06197c340d10 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/syft@sha256:b21b3c157cd0946975310575d95455b90461b3414f4213425eb3549628c9a983 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/syft@sha256:d0e04ec83f6b4fecaf1dd0e67564976bfb3884607d2cbf4e2f860ea9f3eb82a7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/syft@sha256:8ed85b6631f432faa4a9908b2b59bf9243be0729c279e96d829ad90ddfcc29ea |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/syft@sha256:85047c1ccf9cbcba38c30bb3f18d294d5e1008bbd0588c8725a1f1f4b6a6ee02 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/syft@sha256:c86b510d7601196360879c3cf0e84f7e5ebd1d4fb00c2e2190d903930ee31469 |