Sign inSign up
Haskell

dhi.io/haskell

Haskell 9.12.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9.12-alpine-dev, 9.12-alpine3.24-dev, 9.12.4-alpine-dev, 9.12.4-alpine3.24-dev

Index digest:

sha256:64978e1ada7d3250f13a39e1f4e627a94a753a8431d91ea65bb064378fa44e16

Manifest digest:

sha256:ffb89ecf93a48767e5bf16bee393665ea3db05df5ffa126fbbfcc5ec5c951952

Size

494.75 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/haskell:9.12-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/haskell:9.12-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/haskell@sha256:5e1423618ce7e67f625359f6007a6aaf457aada3a4d8ec639d7465979f4cf309
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/haskell@sha256:9724fbea5b5e654f2f0eb194f930c71e1b94cbd23b62602fec48c4eeceb37e8c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/haskell@sha256:dc37ff2670db8ca71a0e6e5b94a23571bb789e460cbb4bdb8e327c56e58ccec6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/haskell@sha256:8554663dd8148d4649c4da2683f561f90e0dbb22740366734a862d8ea11ab654
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/haskell@sha256:0d48c1568f9219e25cd674e4c8e1af81feacb5543c292ba0c02eccce8a954569
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/haskell@sha256:85b3d859023373d82dcb9746e4860f262c1d773056a0813e1047d1ade81ecbb8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/haskell@sha256:6fdff60d77425d6057f673ccde50ac1eb5065ce5290cbb71a2727c7f42c93dfd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/haskell@sha256:fe342451703adfa3ab31965c96d29634a8498164ee61a136a2a4c0605a4e2617
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/haskell@sha256:a9bcd6428ae177506f3472a2329860133179846fe32a3bc23299d11c4df1c8e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/haskell@sha256:49443fd5907f4bb1f3ec2c54e764ed1a813efba12995fded2b73b0fb96106cd5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/haskell@sha256:448bd6916530d2ce16e55165a6ca96188601e6f61eb8c1e0047bd30b29748088
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/haskell@sha256:9aa0302c3cac8b00f15bb36ec371ffcae124b9713d15455e5582ae0ce5151e80
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/haskell@sha256:c01963fa57c0e495e936fe4bbbca711b8eb5a8e953c561366b98277a21438f80
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/haskell@sha256:e6ee150b20ef86d89c762012ed9637c604e792c5e8583fcf034a4ed7e5d7b8cd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/haskell@sha256:78095c489546bf2e8beac0d345db0a35996b0327838af82d73389eab0aa5cae9