Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (compat)

CIS
linux/amd64
debian 13
Tags:

3-compat, 3-debian-compat, 3-debian13-compat, 3-python3.13-compat, 3-python3.13-debian-compat, 3-python3.13-debian13-compat, 3.3-compat, 3.3-debian-compat, 3.3-debian13-compat, 3.3-python3.13-compat, 3.3-python3.13-debian-compat, 3.3-python3.13-debian13-compat, 3.3.2-compat, 3.3.2-debian-compat, 3.3.2-debian13-compat, 3.3.2-python3.13-compat, 3.3.2-python3.13-debian-compat, 3.3.2-python3.13-debian13-compat

Index digest:

sha256:b6523fa3a2b400bfd31dd343caf63652783df1fa8d8f7302e390c3de196e1dab

Manifest digest:

sha256:515b83eb421301dc1aa1278595c7500211c9d705bae5c174e468126b7cd82b4f

Size

385.35 MB

Last pushed

19 hours ago

Vulnerabilities

0
12
14
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:611c46938a4313c6800060a628d52ce4e52f61e4c02e2a60367efb0a8688db4d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:47bd1d639f714f3fcf63324afbf22280487abbaf56985ecfb954da83c19d7fac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:d88e539d581afd9064195eb459aad1f551a3487a1742fda29d5e1edd34bfd419
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:2b7a260d8b677ef450b6bb7aebe9d3df85d408fcca3823c983ba821d6d65b64a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:266c6d0f9c1076a647466cae81b9b3be23187a1aaf719cecbb68ab5a78a157bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:474e5f1146e7ba601d16676f802ffd40aa6fe8b6f5de9873eccc86bea9e54f24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:f63486db5798c5a774f109a018f2c8d216fe6a96124ca4c05c3b19e6ef20addf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:6a3064e269f540ac282249178964e07e49c4ea509231a1948cb2e6b028354363
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:72d138e45bf1bfa15c9a00631b251b4da7b20fb435d08e1545cd274dc7d1e6cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:59091097a4a42c311c5b91161d85f1655b58576c2e0f42f7319c841ee660b606
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:8e31c262fb89a24c90c2420664e673c38205790c7c8a13e7347b30660f6cba72
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:9511ba762e626f40dc7b6b968006e1ba5c4470ad5290303112defecdee620e4d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:db44f3820e5e2e2a19c57ab11c83ebcd47380cf143eaafd062c28533057ffc63
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:30dd0a8b9f728f87907ade8acec5715c4327c652e5942013077e54c6f76bb3ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:edc7b437a7b096619470a483964787a9fa664a18bc10560a76a6f7e8451214a9