dhi.io/airflow
3-compat, 3-debian-compat, 3-debian13-compat, 3-python3.13-compat, 3-python3.13-debian-compat, 3-python3.13-debian13-compat, 3.3-compat, 3.3-debian-compat, 3.3-debian13-compat, 3.3-python3.13-compat, 3.3-python3.13-debian-compat, 3.3-python3.13-debian13-compat, 3.3.2-compat, 3.3.2-debian-compat, 3.3.2-debian13-compat, 3.3.2-python3.13-compat, 3.3.2-python3.13-debian-compat, 3.3.2-python3.13-debian13-compat
sha256:92ac6563f11f5c22b8f5a8a9dd7b9e51be1e36ac4aa0e562c1a24d373884890a
Manifest digest:sha256:99f4a1c0174c4bc33936243b63627ff08303b2239ea4bdf614448dedf8b11164
Size
385.21 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/airflow:3-compat2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/airflow:3-compat --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/airflow@sha256:d9e19f2968425fdd2f2287412c0674fdaf373dfae885a3a84d22abf84c2a7f45 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/airflow@sha256:00da064167f3b1315e5a2979f128bcbac7427e80afbe4acce12f591f2a0eccf1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/airflow@sha256:8e64429d5cfbd57287f18b53566b0716a1f4340b6fcb0e338896278eebb78c2c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/airflow@sha256:962f8d45ceb40b18f0ef6b784d5371dc649ba7f574d0abedd758cc1008e6e7cb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/airflow@sha256:1117a3f529c2031a6213b13f4bfcc3c0d76175219427358b9cf778d2061b8301 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/airflow@sha256:32a36a872cea85b6ad18e4cbe7d8185108109766bcea06d241751189e0f07e60 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/airflow@sha256:1dd42e3b167ebc8100d25e843f1337f80943ee05541e82c7fed0161dc8ec17ef |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/airflow@sha256:cd0c5e6bc014f308831b7b5a76e976728d2213334a67a2042c2983ffba0c45d9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/airflow@sha256:9a0fdf0e45f58f117aba5702a2088d882661505f735e30d7f6c1ddc27c085825 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/airflow@sha256:ae1425c0667027a3d6dd8c782ce85e9ec4da855640cd4982b9ab11e01daae170 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/airflow@sha256:565497fe4f11f56921bfa06f85332259472c644c14c125fb1085501a21442ecc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/airflow@sha256:5e82783c294b229000810b6b538732e6503b8a8860a58056fb01f7fc5a485894 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/airflow@sha256:10e9f31cbb7ff311d1cd114f514cd7e3422947e2c72287883287c1d33de08b0b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/airflow@sha256:40b8d26f4c0ca3125cfdb71e2e1e41b03a0c39084e48e1133f9b65386f799dbd |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/airflow@sha256:fceb3b9a5ac0175166e60e36c0473b2b21d56cfae06bd296c6b24340bd0db05f |