Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.24 Base

CIS
linux/amd64
alpine 3.24
Tags:

3.24, 3.24-alpine3.24

Index digest:

sha256:b18ee573885f54237cd93329a542d526a5aeed79463e5d1f759c4f09269f2ab9

Manifest digest:

sha256:19ebf3025ccab7b73c8da2e559a459c0b8f89250724e83c0b16c116e96b4d9a7

Size

3.17 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.24

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.24 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:16f970c29403c292fede322c0b52af8af1ba03aa8c5e466d16dec2f04bdd86ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:8005439508f989ad712e3b43d40ced9a92bdf6bdd53cb6b00f650bdab368e8ba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:41ec495c4ea2b3dce1f6e24555ecb307fbd1968b9a610a4d89d26aae7fd595fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:78be596ae27d5a271ee6fe51849949d191580759044095662d763c5a0d1cbca5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:a0acfe31b1b9c1becbd0b10df16ef86c6483a35b55cc4ea501420381f864ee6a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:134524b339f93d3642cfca6a38ea462a1fdf5bd79b9c2cdebfcd656474a453a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:4a57d19e7da068bf7c2868c057d60f43791d98c23557df981e2c0aa4c5da7783
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:db2f60ef0a883b7531e47baa3e469b67bbecf7f672e31906751730d3d99dfdb2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:c1823b230aafe81bb37e60b17b43c9c18267f77964fdb4702658633d7a4e0a09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:36d6ed86cc25c2fd86b8b21eeadec6f22ce2277f359c6b0d3fc7dc9be3009b11
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:16cc7645e21ea230ec8dc62c210eb315f69cfdd2ac440b3ee8323d4c57ccf1ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:341b7620140a15252473fbd3624927e0a88240da4344b160fe4f76521ecdbb32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:7f253c7e0ca9311d67a90ccd68dcdebc083901cf2e6d7be84bf0ada6f97e0b6e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:369c806a792753f6b630188f08be38fb28218c09649a11910e8858bb0368f7df