Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3-python3.13-debian-dev, 3-python3.13-debian13-dev, 3-python3.13-dev, 3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3-python3.13-debian-dev, 3.3-python3.13-debian13-dev, 3.3-python3.13-dev, 3.3.1-debian-dev, 3.3.1-debian13-dev, 3.3.1-dev, 3.3.1-python3.13-debian-dev, 3.3.1-python3.13-debian13-dev, 3.3.1-python3.13-dev

Index digest:

sha256:438c04c8dad089fd40c3dccfa463a028369616272b0b32938a16d2e2544fddc1

Manifest digest:

sha256:3b433c4c75eeb1ed84e6e607a99ecd7596fc3fbef33bc7baef11cef149bfb121

Size

78.13 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:2a2438ccbc6df181a45f504c3484497e2bdb12552e53106aeb9d00362d981515
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:a72677f8820e889b59bea2775c970e13d10c957ced850d5ad10bd57f86d43e53
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:8b7ae4a006d7780386898a4bee4fb9327d2c479ddc0a929581dda53837e0e5ed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:86088a3c8aeb74b143f09a1e34850b2d3b15308741f56c98470a4257f68d5c07
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:5417a43512e70dcd15ed9d76805515437611cf8443f6cfaa83996deed6f99a15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:11b0c1b30a380220699e217722f8bbae80d99fd396e466af81601e4e6e004362
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:b0415fe1656c9d43329f98a6881c13bb0190237fe1ba11502c2f230fa9b1632d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:c327f6ead906698a42022408377e3c2aacd5b6be62f2cee3a3112a730088d738
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:d731cc1c0432605838e5077f4ea65fd79cade9e94e1a04ed8d40ef55058191a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:5a0e1b9e7051b26fe8d9e876bc49b41429190b4355624954e5ab79da7d60b2ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:58909047e6215691fbe305263a1053dc6e3e120da0f662abd0a178ab8096cc48
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:0ba45edc562add9903c4147a202eca957be8643d2f8e23a932c047ce4971f28a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:3089d0a07462c7eae7cdae5e2a4e54aad94dd12bd4563dfc4b51e387c192b47a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:b96dadc03f02e09133d8b3cb3bd16ad3486051c2a0392d349dbb96b628d99813
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:dd4269e8d1b4d309de6ba3391b41a475f14a12b77cce4474bc93040feedf1285