dhi.io/httpbin
0-debian-dev, 0-debian13-dev, 0-dev, 0.2-debian-dev, 0.2-debian13-dev, 0.2-dev, 0.2.3-debian-dev, 0.2.3-debian13-dev, 0.2.3-dev
sha256:c8b97c5374b025733a3bb5da05cf961e0190018d5814e4e44458768ba9b953dc
Manifest digest:sha256:1b511719ce73df3e876a1f37cec07f46936cb306ce91581850512960afeb294b
Size
44.17 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/httpbin:0-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/httpbin:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/httpbin@sha256:5be24bd35ac18614eaaf6325b8c4464f5ef55e2460a8962d070c54b0a603d10e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/httpbin@sha256:55f2b9fc71aea6c08933a4bd960d39228012d43fd401388f09bc1f86160fed70 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/httpbin@sha256:1e1a7744e538159729fb916856a6d5e2e9cc32c6d3ef12d2fcb7e918f3c0221d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/httpbin@sha256:f93b2762091b044f30bba0d9fe94ff9f2f2bce37cd02b483a2209a5cf600eff2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/httpbin@sha256:d98b411b40bc0a0546f794e755fa3ebe9a41f949bb96a76a4b0fb4e50e45ec56 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/httpbin@sha256:d5c9d7c06ab60b86da0faae3f46ec72eabf4497c4eeaafc9e10e871bd31e00b6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/httpbin@sha256:eb88659db5befa0de39f53741b2da17cce342fb1522fbe1e76f7417da6b1150b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/httpbin@sha256:a1ccf022e2317f48c2daacba9c4559221fbfd71d4dbce060a6e9885653914fbc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/httpbin@sha256:153e79bca8cba8ee9f69425879729abc45615d0b3fb42fcc4157c5b6b2adc716 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/httpbin@sha256:4f0707d52622a5da7ee3791963d3e33a4e8e0af8614a2dab18b70fda4428d8c3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/httpbin@sha256:8bddebeb2d47ad458122084cc487cd4c3b635de5770479bd0cacfeb5522e3348 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/httpbin@sha256:93643275904ec44d311a5a5d3cb607c4c20cc23528745216d953cec74d1ba7f2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/httpbin@sha256:a536a1c175899728c62ad6ce8ffbfe62eaaebc2e6ffe8cb252f96eea7b03d66b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/httpbin@sha256:967aac3fb5a42561861450cde14ce49ad2fd6868d95bf2647c7fcfc90f1aec33 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/httpbin@sha256:1aa1f5f73cea07b4b6f9f0b6aa5adf9e26552f59218ae7b5c2ba854d81a41ea0 |