Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3-python3.13-debian-fips, 3-python3.13-debian13-fips, 3-python3.13-fips, 3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3-python3.13-debian-fips, 3.3-python3.13-debian13-fips, 3.3-python3.13-fips, 3.3.2-debian-fips, 3.3.2-debian13-fips, 3.3.2-fips, 3.3.2-python3.13-debian-fips, 3.3.2-python3.13-debian13-fips, 3.3.2-python3.13-fips

Index digest:

sha256:646aa97307bcd5ff605a840a8ca406c07045f810a1b0be08b32f204a4fd08ae4

Manifest digest:

sha256:7b27aa4e146baea7cfb075748305c3717be554a8bd687ef418e0dfa89e927491

Size

65.10 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:a4f9782bb7b10092cef2e8c0b06e02cac3b44c37b8919c5f790aab3fc22b7afd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:6b2bdcf93b7898b287d0b46fb9f7324896f2eed92d7cd0dc686c40973ec6c30a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/airflow@sha256:0e2f3d8355142e5599ac14a12a3375d6e8cc473bfdbd4b0f4c263ba34ff399e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:f45000e13ff9d248f09e2d6b635d2eb05dc8d0b62d4b0d91891749c43d205d03
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/airflow@sha256:fbd174d583810230959080955f6f12b6c92927d595a1a9c28994a291956c54f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:47919b119d2bf95f16f8ac4e4cef006d43b0922458a64cb4d27b9f23ee549ceb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:2686da0e89b95df1d7c4a9c958fbc88fc0d2811aaee5a726653b2b1664fdec91
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:32fbb819991b47e78bf199fb5583222ab5cb6f36d9ef666791ac88bd2cee0bbe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:921a85c175ba6463471e3b8a997bbd5f655bb0fbecf8c3d8655ca9cee1d9afa2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:efd99403f6974f38ae93b2a5f98d49147503be13d0c5c671b353f137f33a12cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:f8569d208ada97830fb891f84a81c10f59e495b12ea1cf821df60f7bdeb4d706
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:fce4d666b56e03b1381a62dc0d1dfec4133cafa622f8a6db6d914394140c03b1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:5bec959ea2b68b4d486afff100d942944264f431c3b732d8dda6bc95089a40fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:6404615e22a82fdcad7449f4fbc488c19a0862ad6da086f99a27ce07ec2be55c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:26c21a9a3fa83fd7ed4f6c788eea1be3b8f9d2601b1ecbecbb0f5b23ec7feaac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:9f00027164a6fb88cbf4f1d6ba632bbce969868ebf2d1c21a445f56473fce969
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:90e64542fa5a6edb074eafa4ec69ae62e41283303c6c1f585cd6d40e663434ca