Sign inSign up

timothyswan/syft

By timothyswan

Updated 4 months ago

Syft SBOM generator rebuilt on Red Hat Hardened Images (RHHI)

Image
0

555

timothyswan/syft repository overview

syft — RHHI rebase

Syft generates Software Bills of Materials (SBOMs) from container images and filesystems, supporting CycloneDX, SPDX, and other formats. This image is rebuilt from source on Red Hat Hardened Images.

Build
  • Base: hi/go:latest-builder (build) → hi/core-runtime (runtime)
  • Source pin: full upstream commit SHA recorded in build.yml
  • Version embedding: -X main.version + -X main.gitDescription
  • CGO disabled, -trimpath, local toolchain only
Supply-chain attestations

Every image tag carries:

  • cosign signature (key-only, no Rekor transparency log)
  • CycloneDX SBOM attached as OCI attestation
  • SLSA v0.2 provenance attached as OCI attestation
  • OpenSSF Scorecard: 7.5 / 10
Verify
cosign verify-attestation --key <cosign.pub> --type cyclonedx <image>@<digest>
cosign verify-attestation --key <cosign.pub> --type slsaprovenance <image>@<digest>
Tags

Tags follow the pattern <upstream-version>-rhhi (e.g. v1.44.0-rhhi). Always pin by digest in production, not by tag.

Tag summary

Content type

Image

Digest

sha256:a7eaa6945

Size

41.4 MB

Last updated

4 months ago

docker pull timothyswan/syft:v1.44.0-rhhi