Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.3-alpine3.23-fips-dev, 1.3.2-alpine3.23-fips-dev

Index digest:

sha256:5a121e92d85e82b234c38b552dbbe5005a0fe1ea5970a5a51e1e74d5eedc2044

Manifest digest:

sha256:1e7d0fe711c41e11b23cde4969b851a96d2bd520d3e29c5b5c97784b1c1b9491

Size

11.24 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:fe27625e4814c7a17759ee24ee99d5a939dd7c3cfb22e9880b0e60034693cf03
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:be96d02c76ca68ddf0f41800b809748027445584a84a5ccd663221c41dbed0c8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:5b4ff45225892abc0533133bf15b574f6e37b6a2445af939494ab73f2bd4dc24
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:1beb3fc4d11707d5c1e0d79d10d977877e02b4686dab61c3fdda1b7fb46aef79
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:9d13d798aab2b076407da508a308291638a52409cd04fc508ef898d59ee843c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:dc30ad6900c80045546d0c9f7825b807cfa65595ec3c23833940b61bcb0fddfc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:f9297d87f17d49e7cbdfc8a6871d51f192de858ee97b196acd581e594addb170
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:a5a3acac8489bb5c7990fc916c9702bfc86741a4478df3c9ff339385079986f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:2a4fda8e5ea171e444b2845eea07f21aaf2f49802e1d0ee2ba1e6be0da878adc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:c05f8d40fafc26d8308c840dabb389aa1639324120bc0163bd8707454c191081
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:3792fd360058ff76d62e6898a8bc3b830f0c2d67154dcca04d21562b5a51ee8f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:280c37de259db730d91e9a619190d7b081d31ec250275fb96b163e9fee6cfbdc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:612eb4122cf16d6974dc9326dd7fc179219a2995654b9f1e942c93743e1c5ade
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:017fbc48868ff156edd5b19bec49f94174eed8b6cef56b28924bd9857d21e89c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:4364af6535805d70d9374479d93249f85b288cc11e70cad8cf01be5faea57923
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:8377c718cc5b6eb1ba1da52878f0dac1a14ab8ccbf879e60456343128fa3cd2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:e138a0d066b7ef232e0b1964b6fa692585e8863a1b64424a744b86849931313b