Syft SBOM generator rebuilt on Red Hat Hardened Images (RHHI)
555
Syft generates Software Bills of Materials (SBOMs) from container images and filesystems, supporting CycloneDX, SPDX, and other formats. This image is rebuilt from source on Red Hat Hardened Images.
hi/go:latest-builder (build) → hi/core-runtime (runtime)build.yml-X main.version + -X main.gitDescription-trimpath, local toolchain onlyEvery image tag carries:
cosign verify-attestation --key <cosign.pub> --type cyclonedx <image>@<digest>
cosign verify-attestation --key <cosign.pub> --type slsaprovenance <image>@<digest>
Tags follow the pattern <upstream-version>-rhhi (e.g. v1.44.0-rhhi). Always pin by digest in production, not by tag.
Content type
Image
Digest
sha256:a7eaa6945…
Size
41.4 MB
Last updated
4 months ago
docker pull timothyswan/syft:v1.44.0-rhhi