Sign inSign up
Alpine Base

dhi.io/alpine-base

Alpine 3.23 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.23-alpine3.23-fips-dev, 3.23-fips-dev

Index digest:

sha256:193f6a5cd04a29343d3da7252e389dd8e78a347e6fb96182d918300c18acbc65

Manifest digest:

sha256:6d4fcc9c95f20a1396e5d7c4716aa495285456f95a5d2d2a9b92814375cefae8

Size

4.22 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alpine-base:3.23-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alpine-base:3.23-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alpine-base@sha256:eaba8b61918754588e8c15abae30e24c9de2f2a0ed5bdc9649c8850ba851dffd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alpine-base@sha256:da29b9ac61e90ff64cc858aaa7b91d395214e755139a5ba90f3018e8811e674d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alpine-base@sha256:bc4ae553a08a77a550b51bcc55293580c73432ecf8b6600d186ddd8d79fc1298
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alpine-base@sha256:e435a5babaf40bdc11fa90810fbd37984af65b7b7200b88cd45ce96785220ecd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alpine-base@sha256:3df5ee974f637dad7ad611b1cf192d5ea3015fea458727b538ea2ef5c8f6dba8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alpine-base@sha256:02290d49587fc760286ba6e02bd43c0646f1efabfe3be740b4ece8d5249307bc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alpine-base@sha256:0424f4cac53b86cdd6b158949a6f3c4559213541a2b72a064b1d161d224e7a0a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alpine-base@sha256:d8cbd062e8157131d5636dfad3382f775018fde7910b36f793bd3ef053ca0690
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alpine-base@sha256:d608ebc39c6ed31bbd40290506ee1e8f4eceaa056341a93b9b0cf51a050c252f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alpine-base@sha256:3287a624ca93345e01a17c8cf951f9d8ed16aedc1ae0d683e64e8ce01ed2613e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alpine-base@sha256:ce6c5568ef904991d5f7246c702a5652bc5e1de640b77f87614f7d5f593c8396
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alpine-base@sha256:c5f693e9ea331f0771e20950495b4ee85f38b985f153250f6e038a0ba92ed050
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alpine-base@sha256:255d1ef8d67577a008eebb34aed3833174267eb796dd85d8282039b17485185d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alpine-base@sha256:5c8d61eceead82050ec798c33dde68a3f932239e9576cd9b7745f595f4e123cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alpine-base@sha256:b22dc438b2d48c1353b87709384666b751dcd4cf3483c0d1c45007ab41676d8c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alpine-base@sha256:3bd1b79f3c977a9a798cf3cd2011f19a7f1bfbe0f2c07a21adb42a9fa4e6189e