Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3-python3.13-debian-dev, 3-python3.13-debian13-dev, 3-python3.13-dev, 3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3-python3.13-debian-dev, 3.3-python3.13-debian13-dev, 3.3-python3.13-dev, 3.3.2-debian-dev, 3.3.2-debian13-dev, 3.3.2-dev, 3.3.2-python3.13-debian-dev, 3.3.2-python3.13-debian13-dev, 3.3.2-python3.13-dev

Index digest:

sha256:c1406100c1336aee3dea96df29101f629b079bcc2f12726535a4e4ea06a1ad6c

Manifest digest:

sha256:83e6c98ddc08ebf1090663bfc2a01c87fed98e9fe6ed0c88f3581071b55f954e

Size

78.25 MB

Last pushed

2 days ago

Vulnerabilities

0
2
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:1510807190b48fbe8753b9e3fef30628d7960eccceb19d1b9e2df76e27ec27b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:5d55d186f3670b1ebc892390733b4913c8e1dbd0d0b2a1824d62185ddbc5bdfc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:631561946276413e65beb8babe850093fecb22de40b8c90bd107b144105965e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:f9e13de5057d14e91478959a2fb7454da0b43a2ee63513e550c86e6600ab37af
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:51852524b3a42112dbf4f04afd9ef3b246995e7e59b51ee5dfddd7f5f68a8f97
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:415f1e267f5649b5f523aa4c6967740ce60ec44bd6a29a099896565c33ab5834
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:fc65ee69c2ba08139e894e0239baca26b884d6775abd7108a66005836a027221
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:6b89c1a92e76dabf2a7c914df66fc09efce3a749c88ef54547e394e75c3a9a76
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:70c2aeeca4e776fd21bbda3ce8579fe82be7526ba26fc8ac16fd53d267625ba4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:a3d276548439e7d6fa60e4a740aef146016c0a42fbd3d7f059bdf16248fa200b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:66a7020c3dd8e1b681847aff42eb72537b95b71ffc0ac38f2c32c86e89bf0005
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:5533e99d878d4fd2927a18f1a2e9e9bc6db145b14de0636fbe2a2468be719794
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:15ba4b742d45bd5736f3d4b7b320b5d3268ab73886d83381a6405ebedde012ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:8548b9a25ac73ac2ed909ac9c1add915b612d8467b882d4ae882e764f5366977
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:1ccfb0eaf8ad08e1ddcc30932b8b23f1af7ed4cbfbf6dd13104fd5fc2552aaca