Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.3-alpine3.23-fips-dev, 1.3.4-alpine3.23-fips-dev

Index digest:

sha256:261705eb8948e5558246efdad20a8141dbb150fd66a085990a133d47cbd6a499

Manifest digest:

sha256:a7e4434afe37052568a642c3645d8d321671294e46bf6c65db14eb4060a74289

Size

12.82 MB

Last pushed

12 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:364179e752e7054262efb2dd7f7ec05e7762371a5b1259c54428348a273cbba8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:b3db9601360344b2da282e0c32a15eff0ee4920e50c12f624362b7fb921bdbd8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oras@sha256:a02733465578f0c80433b8fd7d725d5bf981afcc749464105f5ad2cd3e8b24e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:0009d099ec623346c5f4cd36ee5675bf5e320a0028d664cfd12525cf5b35f644
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oras@sha256:ef2d7eac088f1462ec8e2af6ef7ae1b1f522d0c04bdf510415cb4747c452fabf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:74c1cc23334980b850c22dd8492ca6639f62863a566c56a81959decc88978a55
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:17d5ddde440f90a46bfc2b80b1ac3ca4b1ba4c11d032ca943c20a5ec79f7a33d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:b00ec8ed0a93a9578e05651a6929ae78e57d7b2cce479493d18d747944dca412
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:8332de1f4563a804b5efaf52e531a68c8cd926b2a53d00036da02a6ef67162d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:ad2042ffd36f46a00dd04b8f06ab77f1a9e29dfabcd349d28716364657cb7467
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:2707e4a8ad36a9754c5e73bcdbeea3000789fd31ec18c8cd22055f218e715404
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:a9b5bae0f997fb83bc24de0a00c849d1d5a0011865b20c9ccd95f111e5bea51d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:247332d25bf2900167054aaa74d0efe1a62c6e43fa980eecaafab3374fdaa862
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:0914972920ab3d9c804a5c175cc3885c22aee2d8931f8c2a2fa0f4c1e36f4b31
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:2e4258fe46318b4ec710f878abbcc9a034447eb1c0784608963b8d3287b21886
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:5490f49d9cc62e898b2090552814241b4029bbec901c3a4f63cc4e5d1c4f6299
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:dd99637e5e9ff63743044d57cc4ed802a0c8fea8cedf129db19cfc643a4e1b3e