dhi.io/argo-events
1-debian-fips, 1-debian13-fips, 1-fips, 1.9-debian-fips, 1.9-debian13-fips, 1.9-fips, 1.9.11-debian-fips, 1.9.11-debian13-fips, 1.9.11-fips
sha256:fce448940509614622edb256fd5887cc50e3c0b491f2ef31fcaec46a0b32e1a8
Manifest digest:sha256:324ac9343828f90fc8412d0ff0d8d5d22c4fb02dc9f5ec16e9d588e56d8677cd
Size
100.45 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argo-events:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argo-events:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argo-events@sha256:47e53a4398b7417592e2543f75fe97817be2b9eeef2e786a71f6c5bf3ca4e215 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argo-events@sha256:f8c9d74709d98a351344bf25baebe7f82d5ba26e4de16fc7bf86c44637604c46 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argo-events@sha256:929ec8ab0c507da265826014dc9b4ab329e7c943ee837c12304d62adac49ccb3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argo-events@sha256:0843773dba7613ea138b071bbfb1bff176124e4c56713313b9f55f2df1ba6aa0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argo-events@sha256:c32a69763915646d2db601affb8b93a42b6dad0543b6a48a489c9b1fe1a54431 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argo-events@sha256:ac61d76999b1c8bd56cb5a60419aedfc57b14a975431c946f345b9209cf51fc5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argo-events@sha256:298c5e0f865549fc12b789e40f3d0f67f36bfeb99435f2fb93462600025abcff |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argo-events@sha256:866caf535f2a036c083d77ee9ec3251a3b9e6a7d1dab700309d4c6885f28d3c5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argo-events@sha256:60281d46028e6e38b86de2430ae2b8bfe6425b18bc6b151563124648048576ff |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argo-events@sha256:304bbdef3b39ff4e124b0e76440b8ac522534ec74480d463acd96c13ca8723ba |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argo-events@sha256:ad7fd160654a076f60d3d02504aaa6129f2e88dd715ebf0950a346162cb67e25 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argo-events@sha256:94f4671d80b5480431d3c894a752701dc89e15ea8aef6dc310d9f21841f00a6f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argo-events@sha256:b5e5e17b62d09f974d7a7e4a4ef91a4ee4b1f14c9cba7de161d21d8f91b64cd7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argo-events@sha256:087d551f9efb9c3f3b592b79e9d19a196f2fdf58772870c35c78f60fbee67d55 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argo-events@sha256:ffed5516de438f6b840bad4c9a7aa30ed88795959b4b5c6cdc97d95f84ade05b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argo-events@sha256:e9fa1caef9f2b5d42029b903347631dc0b965a799b877b5f68c2a4f91ecfcde1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argo-events@sha256:bb2b5acba4ddbb7d58b05d07db78d6b09ce12ee9da3e8dc5103c646752fa5ec8 |