Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3-python3.13, 3-python3.13-debian, 3-python3.13-debian13, 3.3, 3.3-debian, 3.3-debian13, 3.3-python3.13, 3.3-python3.13-debian, 3.3-python3.13-debian13, 3.3.2, 3.3.2-debian, 3.3.2-debian13, 3.3.2-python3.13, 3.3.2-python3.13-debian, 3.3.2-python3.13-debian13

Index digest:

sha256:11313ade48cad3ea36792152d07258837cdb2777ce1efbe75548ff9d6357618b

Manifest digest:

sha256:98c7b74295a6276869063c2a0f3628a6ceb4dc73edf2ceb674250dbbc58b5521

Size

64.33 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:36aed00f8d676a55b26a1d495f61ae78c29df6e1434e85b0794bd93e502ac5dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:e4f8cd8865b397fc00d25f91573672bb2f2c521329dfadd193523ba693ba9ed3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:5ecb26ebd273063324c4b46f2c01c3b50af4eacf1782e683d3c0f85efd2cbcf4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:9600ba585f9c0f4de6402d54398e1af8808bc193ce637f9db9952a93160f30cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:0afa29f2d3708e5a8cf6a1d8dd7c686a877ef199c2e8e2ab4e5cf0354ee0dfec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:da608872bc0206a0a94e5cc6a8d22cf6a83a4b1a2b40d7be8ed7d5d454bf80ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:946cb10404b6f102799f3526a539a766143505cce1a5aa64cd7aef3427cc4de1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:129726e872ec48b234a9271a6092aacc6344665346c93d5ed632e8de7b27d022
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:957b193ab101bfb23615355973f5558950f96d3f86ca94ce212930c0745094f5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:b16f96068247c10b0d890c37f16e32884e3eb118a392bc87ad82c44077cdb494
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:6d1ef838f47be03f1aabd4e9786070274f47606eb16a6ef5ee1205a37a175041
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:eb1f15d4714b907f338611f4ecf5b94ce83a81a2c21188304b8725cefb4a8e9f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:cf5c3f6a681d8655eaac4cfbc9edb1b225cbb85be0447ceabbc16af0a67970cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:835a3bd7dfad4f5e05232147092c4ae572a5c35d13cd74900d6349e7e33d1727
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:43e49c963874f399cd352d28f036cb6191f77e475405b6c50d079a978e031fc8