Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (compat, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-compat-fips, 3-debian-compat-fips, 3-debian13-compat-fips, 3-python3.13-compat-fips, 3-python3.13-debian-compat-fips, 3-python3.13-debian13-compat-fips, 3.3-compat-fips, 3.3-debian-compat-fips, 3.3-debian13-compat-fips, 3.3-python3.13-compat-fips, 3.3-python3.13-debian-compat-fips, 3.3-python3.13-debian13-compat-fips, 3.3.1-compat-fips, 3.3.1-debian-compat-fips, 3.3.1-debian13-compat-fips, 3.3.1-python3.13-compat-fips, 3.3.1-python3.13-debian-compat-fips, 3.3.1-python3.13-debian13-compat-fips

Index digest:

sha256:a3b2d3edf8d253454b99ae07dc95cc371895dd7c29f2bc8ca44573fab3a872ad

Manifest digest:

sha256:9552a2a23b9112d36b2ab1f8e058ef574c82b1af4eb7ae320da4519353eb5327

Size

381.20 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
4
1
6

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-compat-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:dbbfe274444b5584a93d9286a5915abea107a8ec93cf64200313cf34b655a043
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:4ab3fc31866be835ae52f4ab1d15dfe9091b8c32db7103f4f004169714fe3480
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/airflow@sha256:a104557ef7b708a9ef6b35cfcf1f62de2026b75cdd2549e6c74ca77ab67c26b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:0346cd7e3ab799124d420d10e9d2b0d587b5b07a037209cb4b29613f76420128
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/airflow@sha256:1ded12411b3635c81eaa6ceb73c4fddd771a6e81ea8684672711738638e6f1c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:baf249c21ae70d4252fbd069488e64240808a086aa312e8b5cd35071a52d3416
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:171ae9f9acf8d8f9b1f35c3499f6650ceffc58323599e702f9ff88932e7b223a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:df99c7ba4cd11642ea3b2bcb265ac1872e9f960b07729d61a4f49a5458df0382
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:04dfc566ddccec405501602c57d3d22374eeeb915673666d1afdfd2d601ffe5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:23ee34431c491be2f22100738e0ac59b5f7e42ff4cadbb4b9eae3aed83c46742
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:aa263dbca25adf734eeb55e1476f95e39bdd374f6e41a2ec1fb0a06c00978397
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:8e906cbe3ddbf43e83b4225e5d89d6e49d3daabcc1c3695883aa0f16907cca67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:2e7b78999eb78651f70843d50842c2f48f91ffa4deb3f3b738a13116c349a14e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:46fd50db543b0f8e5129364f78e77d718e4f1a51693b933c53033b5128e03713
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:abd209d955c04b3731df2d1813e2f4b26bcb73b70e30cc17545562bf4580d6ea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:890c34af1f4bc819d0a24d1283e92fe20a6ce9cdab27a6a3035735d523e01d01
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:28c96f3e6825e5eef289324ca010bb2928b4a8478b56f6ea85f1a9fb7f0f14b4