Sign inSign up
httpbin

dhi.io/httpbin

httpbin 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.2-debian-dev, 0.2-debian13-dev, 0.2-dev, 0.2.3-debian-dev, 0.2.3-debian13-dev, 0.2.3-dev

Index digest:

sha256:c8b97c5374b025733a3bb5da05cf961e0190018d5814e4e44458768ba9b953dc

Manifest digest:

sha256:1b511719ce73df3e876a1f37cec07f46936cb306ce91581850512960afeb294b

Size

44.17 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/httpbin:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/httpbin:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/httpbin@sha256:5be24bd35ac18614eaaf6325b8c4464f5ef55e2460a8962d070c54b0a603d10e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/httpbin@sha256:55f2b9fc71aea6c08933a4bd960d39228012d43fd401388f09bc1f86160fed70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/httpbin@sha256:1e1a7744e538159729fb916856a6d5e2e9cc32c6d3ef12d2fcb7e918f3c0221d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/httpbin@sha256:f93b2762091b044f30bba0d9fe94ff9f2f2bce37cd02b483a2209a5cf600eff2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/httpbin@sha256:d98b411b40bc0a0546f794e755fa3ebe9a41f949bb96a76a4b0fb4e50e45ec56
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/httpbin@sha256:d5c9d7c06ab60b86da0faae3f46ec72eabf4497c4eeaafc9e10e871bd31e00b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/httpbin@sha256:eb88659db5befa0de39f53741b2da17cce342fb1522fbe1e76f7417da6b1150b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/httpbin@sha256:a1ccf022e2317f48c2daacba9c4559221fbfd71d4dbce060a6e9885653914fbc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/httpbin@sha256:153e79bca8cba8ee9f69425879729abc45615d0b3fb42fcc4157c5b6b2adc716
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/httpbin@sha256:4f0707d52622a5da7ee3791963d3e33a4e8e0af8614a2dab18b70fda4428d8c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/httpbin@sha256:8bddebeb2d47ad458122084cc487cd4c3b635de5770479bd0cacfeb5522e3348
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/httpbin@sha256:93643275904ec44d311a5a5d3cb607c4c20cc23528745216d953cec74d1ba7f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/httpbin@sha256:a536a1c175899728c62ad6ce8ffbfe62eaaebc2e6ffe8cb252f96eea7b03d66b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/httpbin@sha256:967aac3fb5a42561861450cde14ce49ad2fd6868d95bf2647c7fcfc90f1aec33
SPDX SBOMhttps://spdx.dev/Documentdhi.io/httpbin@sha256:1aa1f5f73cea07b4b6f9f0b6aa5adf9e26552f59218ae7b5c2ba854d81a41ea0