Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3-python3.13-debian-fips, 3-python3.13-debian13-fips, 3-python3.13-fips, 3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3-python3.13-debian-fips, 3.3-python3.13-debian13-fips, 3.3-python3.13-fips, 3.3.1-debian-fips, 3.3.1-debian13-fips, 3.3.1-fips, 3.3.1-python3.13-debian-fips, 3.3.1-python3.13-debian13-fips, 3.3.1-python3.13-fips

Index digest:

sha256:c2d6fa7fe76c3378dce53fbaf410cecad45bca16117889afac66ebbcf55e1cb2

Manifest digest:

sha256:9cacb25c3aeee46f303195fa27695cf2d51c7957e57c010a3edd25d0dbea5e5f

Size

64.98 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:dff21dfbd4fe9e67aaefcca2f0460503b824e66fae61ef9b644dfa1d500ec8f3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:6a9b0e68cc1a56ddd3f433819ac365521de728af9311bfdb32d8d7a7bd6a583c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/airflow@sha256:d5314825ff3e4e9ee8d145ba779e285d3a9d04e46ab0c9e1b8d2ec9bfb230f67
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:be905effd67fc23aae6aba29c0ffc9e6ba7b2057da6b527ea3ae59a41769fc1f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/airflow@sha256:b963dc911123bc3319f89bf66363c8d239d3aaa323714ea419b50c3658b78ce0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:979fa6d6950ca6aa8769c8f373590db9514d6b3e59394284739aa6bf8ad90432
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:7bb072f6dfde8a97e4f37a0b61c1b8d3405b5147c28b315b5425ef9f4fc34503
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:5c2d30d464d66d782e19f91d1e61b09a07d1df1d33fb5f1342ae7aec772cb5ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:70621369aa53d23ee431bacb0a518f377698b3ed831e551a0973ec26d5ad9599
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:ce01434d32c8e90d9354237d39f70f0c1b4cb6e4e80330b991a5487649f4ca31
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:5b4f2e54a09ab597c571284a92be07de1cca2e96e2c7b6e64b2642253a930cc8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:18107be5474bf3bbe5b662536a21c80b313519491750f16822693fc3dda73f35
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:6f1e0d7d71068e030b634f45ce55116500bd6d4716664a27fe037a640b6c6fec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:955e71f22a2e1fb8866cdffec3a860096486eb1e622fc8f927d3411138a05b9a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:5e8badbde1998b96fe9dffd43014d6493e9a85ab6162611f3f5bea1fb1cde246
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:8dbb41e7464d8b4e7ef73cd4b981001e565d40da77ecb1aa6b90d0ffa52e4d2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:d1fd876ca39d43f111fbd4be58becffb7ac2f16928c83c311dceccf032e8b80a