Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (compat, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-compat-fips, 3-debian-compat-fips, 3-debian13-compat-fips, 3-python3.13-compat-fips, 3-python3.13-debian-compat-fips, 3-python3.13-debian13-compat-fips, 3.3-compat-fips, 3.3-debian-compat-fips, 3.3-debian13-compat-fips, 3.3-python3.13-compat-fips, 3.3-python3.13-debian-compat-fips, 3.3-python3.13-debian13-compat-fips, 3.3.2-compat-fips, 3.3.2-debian-compat-fips, 3.3.2-debian13-compat-fips, 3.3.2-python3.13-compat-fips, 3.3.2-python3.13-debian-compat-fips, 3.3.2-python3.13-debian13-compat-fips

Index digest:

sha256:f841d72b1a399cd38f33093832855f16a27b95c6ac40acfb7dba0166811929d3

Manifest digest:

sha256:44e15fe56cef520ce40b9ec53fce033798a9ffdf68b22d33a3c73e06f802f85b

Size

386.24 MB

Last pushed

8 hours ago

Vulnerabilities

0
16
17
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-compat-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:af20ea5d19997607557f7fcac861055ffa138939bb7a7caa60f69de2b2f8d802
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:aaa15c7bdca4f3805058a253550d38a31df4938e1f69dde105ba3834e5408257
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/airflow@sha256:993784dce94133c04cd05d6fcc91dd29317562823a026bf006d6e928e33ccbd1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:a6afa396a05b962f6eabe408a90ef5d5b5b18383beb53411c2f155587bf8ae22
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/airflow@sha256:f9dbca423ee3fd324e6ba72376e02258cdee1a2bb713caf00d95f39d6f9dfd91
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:0e4675a6a088418e2c6bfe5b8c8028afbec133a7a26ad27aeaf57d9a530a3f9d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:a86f0864ace5630076c1cfa43e060ab22099a99d3ce40c33d08530579adb4351
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:0e997c16b5caac2a5f4bbe6c243abff971fb17f942ecceb34b6e4650f4523b58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:b72f34e36830382e8a06db0d0903658a8ab5541a79879c9c3aba487fd345dfd0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:a7e7fac279f9dd0f839f7a75b44eb34b1482307aca7573afbba3f2bf6b84db7e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:671d65d7b19db804bca62f8c99e6d6bb1fd0081ba960c6d3d31f39107deb01a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:66f291d8aaf9aeb837f7ee5e01f871a7ae15430fc869c86cf9d4dad5c077b99a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:bf1f2fa064ff0b3fb01339be9d110933f26486b50dc3e0b450ccd330128b7da8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:24bd5ab7c40d599a24936742ddf0ad9442d229fe6a400bebae0f94c652015b54
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:4c691da2e12b991d0f2c61405f478e28eb9234feb674d0fcc2a35a1f3731dbb5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:58bff810da928966609e6e2ba469c1d3a6b40d85000a4549ee623d36ffcb61fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:92d7e87ce1d0ea5b8e70bb07aca4c85aab9695408e637c626013539968e80d33