Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3-python3.13-debian-dev, 3-python3.13-debian13-dev, 3-python3.13-dev, 3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3-python3.13-debian-dev, 3.3-python3.13-debian13-dev, 3.3-python3.13-dev, 3.3.2-debian-dev, 3.3.2-debian13-dev, 3.3.2-dev, 3.3.2-python3.13-debian-dev, 3.3.2-python3.13-debian13-dev, 3.3.2-python3.13-dev

Index digest:

sha256:238a42cdf0f714fc4e3997e3916ed36d90df35c601b4409a271e49c3d8fd0235

Manifest digest:

sha256:f120f73a9af3cd0fcf93a78e9460ced20df4150b4a8e3c1fc6989fb7cb4ae48b

Size

78.25 MB

Last pushed

1 day ago

Vulnerabilities

0
2
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:2d67361a51d12c9e9903edbab55ca4060e4b475bd3cfbfc9c96977eff52a645c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:23f0e034da5b1fdd1011d03a6c25f200f3946486c47909f7fefb5184b195cbe1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:79f77636f5a4a5ad5d2f0cede3f2cdeedbece27cff0a6f3397c62764b3444c1e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:eb3021b36245807fa37667925d6ba9221075a7135d64183cc2e8d0ccf2dff47e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:8cedc5a1961310ce4767985d1be7f97d5fd472888f37e0d5d9cb5cc0d072635a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:a6dd03c676d56ea5664f428419ac171d26751dc03e5a306f88e9b5fefd93b8ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:20e04144949afab5fb205d5af44d4bb1c21076b62f9f8978a299134f7ba62f4b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:cadb0ffb6605716d2a91ab44e2213023fa892592f985b46a6122f73773064785
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:275111d888a8424e7094d2efeef1208c68ce1657d35f6083078b8b44fdf9c4f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:9cbd255fb225bc94b81a8974a3647cb6189bb271087a53bcadb60e4fae642887
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:81b5214519f3df8e6d6bcb6d78e12c4c0e0d9f13f05a76b35e1e7e7f7d1bfb90
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:a9896e00eabc73add273e6206b99f9fe8d590044eb3646ddbd2279c625c5c7b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:c982acdd87b3b6eb837e41029cb572cbbb65731a9f7113d8e4f7cf73fa655dda
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:4f75333ac8125f42d66c18baf34dc4ae00afb3c0f537c5f65c8b5e1de219f7f0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:34a1aa024ffced9197b6abc2cb367e851c7a02366a81ecd21a86c95d5ba7e25f