Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3-python3.13-debian-dev, 3-python3.13-debian13-dev, 3-python3.13-dev, 3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3-python3.13-debian-dev, 3.3-python3.13-debian13-dev, 3.3-python3.13-dev, 3.3.2-debian-dev, 3.3.2-debian13-dev, 3.3.2-dev, 3.3.2-python3.13-debian-dev, 3.3.2-python3.13-debian13-dev, 3.3.2-python3.13-dev

Index digest:

sha256:13d6c3869ffac5ca729c9260457cb13171d55f6a735d9e851484dedb516d4b94

Manifest digest:

sha256:b62ff3ca22f1b9360edb08ea00b2fd54ec80783172ec03c745e62d65b585f49c

Size

78.22 MB

Last pushed

20 hours ago

Vulnerabilities

0
3
6
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:c2ee2e43a662158531c06166d6c3b97c3d1af4320017c87cfd09c36a36550832
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:fa3c8b9cce977d160787c170b3be0b3e1240d7299ab58dca6bf11d3050411d0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:ec77ce2826061d464c2cdf3817665af0fe3404a410c5ca0a3d5f172da2925a72
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:5b54c5e889c40e1cef17f982d929f7ccb32e9a0e7ffe218b60b5d9ac9fd90723
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:b5f57ee773827b97b0b85d87ce100f019322f1cbb98fb213a4b15e69c20c9931
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:5283b50c9e526a87936589150af8ee8eccf6ba20c65489c8b0e1f6e76b9e1de0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:0ac475cc459fd498e700ef616ea1ebe12a5c378a61d83e7589423522bfa3c69a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:ab72d3ef9a93a1b1c5ae6ad001c6cb97b40d14123454d17f8d4494e87007242b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:63a76e406646932201d9bc84064ae6408a25d852473717e42740b0127ef28e30
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:eda94b0d7564b9ece147a5ee800be30c936305edbb191dc1e875f1e7c30ea4c7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:c150baad3353f0544d921a637866a0c54758324207a334df6f2c6acd5cbeabfb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:07bdd9f0bf95c7230fc46888c7f34308c8daa52560ae492cbd16be377932596f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:128cc0d96af6f704028222da188c37dc231184ad4ab6abc7c6d4309293a1c341
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:9e903c4597aeea11b9208f439f544a56765879cbfb494e674f89933f40ca53b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:7dc923a7b104b41d8a828a66c06869e318c7a30beac4600e018a89b84aeaf1ea