dhi.io/chartmuseum
0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.16-alpine-fips-dev, 0.16-alpine3.24-fips-dev, 0.16.6-alpine-fips-dev, 0.16.6-alpine3.24-fips-dev
sha256:91b6efb5c017d85921874e49cafb42f0f284b176f5a00cd424e6ecc51c56630b
Manifest digest:sha256:3ca4fcbe582995dcceba4e407cce2c615d58b900631168799a20516244e9a57d
Size
23.66 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/chartmuseum:0-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/chartmuseum:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/chartmuseum@sha256:bcd8574dc79c9becad23e307774d4cae03a828938bbee80a57c63d05443066d5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/chartmuseum@sha256:e8103143c34338944e94af27e66561bf624f2bd9cef3112d3aaa3bd318419ca1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/chartmuseum@sha256:3863e6ba74dbb6c0e1281badfc8a1c9b6f925e82bee4cf6da35db9122692ba6e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/chartmuseum@sha256:5e71f6c879624349ea74ce8ecb50c5ee201dec9a7cdc77d43fbb62fafe67e48b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/chartmuseum@sha256:1985e13ef0b756914a63a72a182434170139dbd610c8f1d0b8dd01267fb2721f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/chartmuseum@sha256:36d36246c239420c52469b247aaf9620d7e972fe971fc74cc59efe1f5539c291 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/chartmuseum@sha256:0fc47a84f29de8d63ad70dabcf819506907f09864bf7a52a167d3162f249a665 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/chartmuseum@sha256:f062153da07df65ce70612e1a2e73e5b9990855e279ec660916698db76f7b269 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/chartmuseum@sha256:9c0f667b84c3a6bb601ec239d65626b9bc7bb5ccf6226644b90e5445dc75852a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/chartmuseum@sha256:149667540f18c8c08ba25affbee26c544120287dbcecd9e2cdaee39654bf4143 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/chartmuseum@sha256:777ce86be38e6692d56c54450552e78041fc7205082cd9dffc08287cff615031 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/chartmuseum@sha256:4eee85cdc2a3f20e664862078034f3766ddd3d503779aa297099d15115dfa36b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/chartmuseum@sha256:700a774166224530df4bf40c5cdfc3b2f92dee5863b385b00e339c0cac444166 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/chartmuseum@sha256:23481c39ab8165ef320a9e357e622f7eee47f99a61bf2d27b02ae83616372168 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/chartmuseum@sha256:ff344bcd49c40fc4b832b6f996ea00084a8cf20b5f442625e584f94092d0c638 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/chartmuseum@sha256:906f38985f22cbe1da9afb218959c7083bc4bf73aa01f3eabca27b2df7d99c08 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/chartmuseum@sha256:0ac162dedef79361022c8db2d309d55cc19847af12edf77d9bc9abce221c0f8a |