Sign inSign up
Argo Rollouts

dhi.io/argo-rollouts

Argo Rollouts 1.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.10-debian-fips-dev, 1.10-debian13-fips-dev, 1.10-fips-dev, 1.10.0-debian-fips-dev, 1.10.0-debian13-fips-dev, 1.10.0-fips-dev

Index digest:

sha256:efe46b2aaea528ce6f43b7a5510714ff690f39d6ee284910b7b0be8e29db8fb3

Manifest digest:

sha256:b797b5f038638b3b777c1ffb2c61c3c47308b641ee48afb8252feac989607208

Size

69.77 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argo-rollouts:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argo-rollouts:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argo-rollouts@sha256:7a759fdee305fdd33918a0e1880c032da5b5d98b3b42ce3d7df192b427ef0064
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argo-rollouts@sha256:2339b9b957d663eda594dd7b097d9646dbf424533ab2b736316e1d5ee985ff21
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argo-rollouts@sha256:136d6d04bcee1458872093a2657498c37e77d598077bcd6cf4eb68184de29ea5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argo-rollouts@sha256:2f294a0dccd3f5277ab2185675a454b1da4bdad47403b9628ae5b83bde3dec28
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argo-rollouts@sha256:933d92581b3aa4ce17e04519dcc0104d1360715bdf91ed70b7afb335f18ae283
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argo-rollouts@sha256:15e90d5efed1df4ab61e79cdeac3df96cbd646ba0123a1eae7c0f8fc9c919c90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argo-rollouts@sha256:d8f6173d3a0cc2c33aef4d7ebdccfc871566b90f6c46bd19ad77d8ae39110965
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argo-rollouts@sha256:9be4f5b1f5e8a77197a88b0ab44e3f44625fe184120bca59562d9ae98a096c7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argo-rollouts@sha256:e2a8ebddd20a8e7d7396715bc23d7803bbcaf579e4281ce79d1703a3f03520be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argo-rollouts@sha256:762e83c06d4c2448edc66a3462f9c42ab68afc7d96b333a01c398e19c93cc5e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argo-rollouts@sha256:01faa9f1e49c6048e80078f99eafbdc48f8d53be5b71e46dbce88b7a72bf2698
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argo-rollouts@sha256:92acb41b373234b302cac1a4f46cf3f648309547c9b2e3036191ca55ec044e1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argo-rollouts@sha256:17a81f254809cc769f631042fc224943030c52152dcc8311aaffc1f4cade50db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argo-rollouts@sha256:12947480c13719300ffc185126eb9f60f2459396faa7d76de80b05b271a4881a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argo-rollouts@sha256:3c096067b77c8ce56699cf6ab71045d0e47dd7160722a52fc8270deed2294c23
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argo-rollouts@sha256:9d66f2afc762d317e9ac7cbb61a1adf283ac29641b80f92109ccaf7d6d7d83e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argo-rollouts@sha256:3520519162e9af8a50b6c8b451194c4b190de35ebc0446d7a4d24a10ca6c29f9