Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (compat, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-compat-fips, 3-debian-compat-fips, 3-debian13-compat-fips, 3-python3.13-compat-fips, 3-python3.13-debian-compat-fips, 3-python3.13-debian13-compat-fips, 3.3-compat-fips, 3.3-debian-compat-fips, 3.3-debian13-compat-fips, 3.3-python3.13-compat-fips, 3.3-python3.13-debian-compat-fips, 3.3-python3.13-debian13-compat-fips, 3.3.2-compat-fips, 3.3.2-debian-compat-fips, 3.3.2-debian13-compat-fips, 3.3.2-python3.13-compat-fips, 3.3.2-python3.13-debian-compat-fips, 3.3.2-python3.13-debian13-compat-fips

Index digest:

sha256:1696799d14b86680355c0134e10058cce979f798cc2c5fce97071853ad9b1b7c

Manifest digest:

sha256:8c8ed73233feb12537b252ed213eac90cd3b58a527c0cda9d91a4348a6b74066

Size

386.11 MB

Last pushed

9 hours ago

Vulnerabilities

0
13
21
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-compat-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:923e18c3b09e91c61671fb691bfeca8e6381c6fd62d1c33a0d0b985737f833cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:983c88207235d19a998b96b42f93a0ff43249f98754c68e63ad21dcb15709815
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/airflow@sha256:d0807d3375d7c18d518494f9a382f0ef29c7b3437a058dc86534d4172e7e80bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:4a97e92ce8d6bcde3c9a1f8820c228d36d8d0030e2d45ea3d2a3939cbe576fcf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/airflow@sha256:f66c86c3e7a81220d8d755008a67afa939a3b891548d2ff5657ae968f62cb9b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:80f36e9e8b81a1b4a48a55cd8b7bf6d1b1860f27fa7469e6c2fee9602ce6802e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:9391664d9db00dc809363a3b42d6873a6d4bd99ddaf35987a153a38bbdf32ded
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:7c20078765a6e51e6855b8574ec3abc3f4ff7676f9f07a398cc00088d4659eda
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:5213588235dea6e8f10ccaea5960d299027613450d86122d2104aab324cb5170
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:601de96804ff08aaad41176292fb743c953173e327bab3d0bddf11519a3cae66
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:ad1e210b71b2f61e665a4b890579c7f0413022a5de75e8691486602769fc6178
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:30c2fd86ef4a9c2b3ce4b4c194195327acfa3cc2238a8d9123c58e79c60cd7e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:a19686f145dc1039fa5a662df86affac041286268a06acd23c0c9c129deb9c4a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:8977366c6ff46c986edfe401e14ce5622252be0b84579a7c82d9d0d6e174f6e2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:87df4da4e1f89c3e570fcec1e68d45ea9d92b4498a6cde27363f3a644805abbb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:1b299ec299f2167daf4be4afa1bc468dfd5bdad3e8ba7c6fd7ba465143ed147f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:87f8bd1f9b477c515a3520879606bc4b1166458a98019ca80233029518872d00