Sign inSign up
APISIX

dhi.io/apisix

APISIX 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.18, 3.18-debian, 3.18-debian13, 3.18.0, 3.18.0-debian, 3.18.0-debian13

Index digest:

sha256:20fc4b416b28cf62224b634738329c88c7a8fc1084c77bb611786cbc0dd35579

Manifest digest:

sha256:0a479e3ae97a8d6a0fe434662d39714a5238ba756c4bd4363a7a1838edf13c65

Size

69.01 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/apisix:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/apisix:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/apisix@sha256:24d4313f68fc66fb6ba0c4d113a3b01b5962e806536d62dcc30b80e4af613a2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/apisix@sha256:83064b32b78bbe69b6283d9c6f4e0eaee629fae80df945a2408b81b96d9b5691
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/apisix@sha256:e5a40e4a52a2fc73162500ded3f4dac8db6e76bd8c78696b7ad9626d4cfb5cc4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/apisix@sha256:280e3b01660f81f9644a5edcf464970f303d86e0e88099acc47d8b068e562da8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/apisix@sha256:4235d7864049f65242fd44659e562b2fb1accfbf1a39402bbda8a5601358cfba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/apisix@sha256:3418931b7eaca397e98cf3d91dce8e39d21ea5db9da6897cde895841a30ff458
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/apisix@sha256:af7abb510fa6bb9ba7c7506e18f3a06a98f3572100c6dc3944c2e7ffd5c5e199
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/apisix@sha256:20403b69799428cd994b03ff2d371667c9d3728c10a2082a44d9c0b57bce7c74
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/apisix@sha256:6bbd35faa235b051f018992c729ec3eb1f7d3229c2ecc4619838f03c85a806f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/apisix@sha256:a27f86314076dc9b697a02088d80af6f52fbf1c8f6b29d57e50970ff81655031
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/apisix@sha256:4ba1365b1d703f1e492937ecb042758e848ba0395dd17e2d85ae8cf9362e564e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/apisix@sha256:35a12b3fad1efbb4511f0a09ba58619068201d9dc931f3fd9b306c0ec60b46b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/apisix@sha256:036e95f72dd378aff46df200a5331ae8d7d7952bce6f1695edb7476059bf7c99
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/apisix@sha256:5da35c3764f7f50c5362a81047274e2955724dd10ca9b8399e6a04d89f89c03b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/apisix@sha256:154283821ba6de7d45c2074e6c979b18c175f1edac2c15186a87f0fe4a2facb3