Sign inSign up
API Declarative CLI (ADC)

dhi.io/adc

API Declarative CLI 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.30-debian-fips, 0.30-debian13-fips, 0.30-fips, 0.30.5-debian-fips, 0.30.5-debian13-fips, 0.30.5-fips

Index digest:

sha256:dffd2129ed12af65d5919c45f7270b40c0364fe2362ddac0b077d768e5d283ff

Manifest digest:

sha256:564067f47f1b321b589d5eb5cc4a287881c2c2f89eaa215ca5cd7b74d1a8af78

Size

42.66 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/adc:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/adc:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/adc@sha256:0acb50dff17f9fa91142f5801a367425ca6b87f4d410524581187805b44b7169
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/adc@sha256:0b5142b167ec269c1037886652c463d2b08e5cda46e9f3cf458a2d42bce4b0ad
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/adc@sha256:21fc7177c2f1cafc07309b1f17adee715a4fb54f0cf0fbda64b32cd21705e467
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/adc@sha256:cfb277bf2937dbe3bb026c0bb64a089db5d060d2bb86a145053332bc9ac7f33f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/adc@sha256:9ccf749448a90441da2044e5220a37c60aabd1add92ff496dd89f0058ca02123
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/adc@sha256:0f325af47841b93f956405ee1d0a382738aafdb9e3fdb662a2b9a954d41b41b8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/adc@sha256:ac4b8a00a8d8558bcae6319149864684975f4353ea8494f21cd1e96bead1f9fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/adc@sha256:90ec54b9ebeaaf74d0be2cbf60c71e446e01aadb8ac137a658dbcab274c7bc94
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/adc@sha256:ba09bea5eeb3c2bbb3805aae758e1bc06b7e779aaa69ceac4634be8a9372917a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/adc@sha256:73e544091defc9e37e3032c2f4ce4a3d90e198611417a11efab1d1e90221b555
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/adc@sha256:e129775b9058b1365b5714bb630076e22d3763700ed85ad00bd5d7dd925c5e32
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/adc@sha256:265237d5514d451454d44dec6cd632b5d28fd683fd4cf12ea1ecc14d434a66bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/adc@sha256:38ba46fdbc4245df8f0c4ce610da9bb093836789cc31f4a61488102dde7a53d6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/adc@sha256:eb8362df7297de0c8f411539b7ea4e15a180e46362050eead2e37a6339e47bd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/adc@sha256:6571c499a451cedac765daf4d01997b3323a919c3e6dc04a0ff87717d727d4cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/adc@sha256:e3e1d1dcf1c07a6ce2fbb88a448bbae68b11d72d98d96fd8d6d9a595a1b9f238
SPDX SBOMhttps://spdx.dev/Documentdhi.io/adc@sha256:87474425e50cbe369eeb0ce04f951436bc4d909056efa250cf5b41a306ee6a22