Sign inSign up
notation

dhi.io/notation

Notation 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.3-alpine, 1.3-alpine3.24, 1.3.2-alpine, 1.3.2-alpine3.24

Index digest:

sha256:41a377d4dba709281a0471469a9b2eed1c70ab78511489bbc9407d953aafffea

Manifest digest:

sha256:4b614d00ec1b1d78cfc433344588026b31ad262218ad53e7454bcb76e19ab240

Size

3.77 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:3c7218864884ebcb86b7df90ca6a6f1c63ea488ae4c03bed24295888e1e4be13
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:cfead7a92fdb9810d7959699e93a2db18fd43f52d087f37c16592dba8a7f2888
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:e8b6890cb27f98398ad9216ddb3ffaa00339a45de479f94018d06a694a478db9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:14ad9264738a78f8efa74403830df28173bee51ef7b72403269d8e600ebd0626
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:462f7a18715c8f547929c5be8e1cd13c1129c851124e594146c6c34f8444a67a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:71773ab19da18b2efd312d157ddbec8c2ef94fbcb1c696c5cd37fa2a337589ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:715cfcc2e31e578703031d440bc806bcefd002e7ef993b04a9b9841cbb48e674
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:0c47b592890e2f63009ef8156a9af7190fa0673c0e7436a09c51f26d79b2cf3c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:11f24f4f317b71bf65ea234608a35b370c7123d879dfabc403e33f1f8cea8d22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:4556bbe073ec27a0f9a1e9223f225da91db644c7cddbd93f5fc430d47001991c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:3f7cf9822da14403d19c63f9e5f96bb2ddab7c2f2ca35f40bb395ece598cd5b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:7c5a348528a2af003a3732dcc8afda9aa7d001d8681fd9c10d3df4725a6beb88
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:527bc9a9027abf5fd097e02cc508626d320d97b2cb21253ef299ec4126182e10
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:01e462825e52015d723611f55a4e5c0949073245ab31fadc88e49514f6e234ad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:57f44cadd116c0b4772639ddd7d2c48b6a86a0cdbf6b001c946dc0db5edf01e0