Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3-python3.13, 3-python3.13-debian, 3-python3.13-debian13, 3.3, 3.3-debian, 3.3-debian13, 3.3-python3.13, 3.3-python3.13-debian, 3.3-python3.13-debian13, 3.3.2, 3.3.2-debian, 3.3.2-debian13, 3.3.2-python3.13, 3.3.2-python3.13-debian, 3.3.2-python3.13-debian13

Index digest:

sha256:a8a3c71b4099457426ba56557893086ce0685d767a443632d20c6fa7514cfc14

Manifest digest:

sha256:6d005a6379f33b0e794cce5979a0cfa6087c50a249ec114e6d318bd7bdc517c3

Size

64.32 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:bf8f514cbdee63c5d26fdaa9f15fcc13bd4629edf21ac5eb1ffd9783fb1f5f3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:699b5dea37eef21db57792d61d35a5e0029f3b4946f85ebfd922e761849401c3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:3766f8afabbf5a5281fb95aa62d5dfaa71e9d8f8343d39889aeb4f283ec92f33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:6ce1ffe76ac84ad5419ca549f433d63ae68882c86fa8d8f21c5b9c545452942a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:169dcbf04d82c5bbad97e73c61fa74c8a909f4ea66b26e5c5dfe8e887e1bc678
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:47d42f36571004a1ccc76a22981131888137b3d1879faaeb4d49d6ff5b6247af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:a56a74c7f4e0e1cd9c14ecbf4aae55f041dc47d84289ea1e8d4d99ca9d5998f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:0d5da459f5a23f5fdc0d0e91ed824a405280ac095c6794501c9ed1ecfc446eca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:2d1105cfbfcb66983b78bbe3d9b35f4283023cf0d568a4ccb387edac78a57ab0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:0fb54333f4844dae49500e1609bbbbbf268ad9bf4adc2c38f1b11a91280bcfee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:c50f727b7939d243511ee7c707e2108716ad50dd6f4546b0ad0ff53807071ed6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:2656d545d04021b26203911d87e2db61334e87fa6d906725a2e77f1bb7211b61
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:648d8969a101337fb1ca5b525c89e28ae771bc6a1d27d6941dc7bc3317a1b4c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:5fa6f6746994f9dde960b87032203299d17487c4ef729adfef791c6564ebcbe8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:f9f65b6e70354a2a2c75efec3a0bb6f266ed1c03586f4adcb2b278fdd22cf224