Sign inSign up
APISIX

dhi.io/apisix

APISIX 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.19-debian-dev, 3.19-debian13-dev, 3.19-dev, 3.19.0-debian-dev, 3.19.0-debian13-dev, 3.19.0-dev

Index digest:

sha256:f317f3ad022cb48ea935d2236be66165bec228a1fd498a198c1b3474736493d4

Manifest digest:

sha256:2644d4ab9140231f6f3374b1cd827c52320ef46f39021239958293303aab7384

Size

78.05 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/apisix:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/apisix:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/apisix@sha256:94149a2be8e34b01babd2155b6946259f872a6b851c83ce467ae03a1f1026cd1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/apisix@sha256:e21498d487242fc1b2916bd69c018fb1dddc677f45ae8085ed4584e68285f810
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/apisix@sha256:6e55165ae7ea519b7d3bac4f56bac5f2f990d45a07131ab6b24ed78c553bf649
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/apisix@sha256:638658c09a512c4459c6e1734e1a3b70d486c4b7db2d6c91ff76a6fefd826e50
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/apisix@sha256:f6a2ce41dbf760e83f82c591e194e98edf19ddc002f2c4315c54537d193430a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/apisix@sha256:8ef4dda510a8f43a32c717e27c5672678e845c9f0ef1d8d2f3efde4ac5a7af3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/apisix@sha256:6bb91a3d5ac9e2350222975a4e479b5789ff0dae85ffa27c239ce5d15a9233e6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/apisix@sha256:8277324a6e41b47b33ee41763ba2a799ea04e908d463a1b4ce232d49939552af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/apisix@sha256:3c0967591c7bb4479f70c5be9515e8c5c97628f7a912e121820820a62ee6842a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/apisix@sha256:2bab740912b7d9d44bdc5837fa0f684a1ca36daf10d283ed6e03e88b3c19ee82
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/apisix@sha256:2314d2177e223ca2d3b9b63d50ebde0d673828e3c88cfc1bb6ff22f07087db37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/apisix@sha256:865e4c4bb176f6cf936ea6d3af5dcc4fb2c883ea86aca66423ddc4295bac80d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/apisix@sha256:a5d3725dbdcdcf6e3805f8bfba5b57f7a857d89f3d4e653bae3d9bd00fe9d7b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/apisix@sha256:40bd99692947cc447c5b95ea192e43a7fca4d34dc55a2b7836c1f1c6099b798b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/apisix@sha256:04158207b9b83668c8c46574e8962e42090ff9c84ff9bc43231f0813bdbf8ff9