dhi.io/argo-workflow-controller
4, 4-debian, 4-debian13, 4.1, 4.1-debian, 4.1-debian13, 4.1.4, 4.1.4-debian, 4.1.4-debian13
sha256:9f266926bc64661f6fb2d987a3a8f7a0012bca365c91d0bd011253623cae6954
Manifest digest:sha256:1aa583592b64223ab008db68ab8d4151a65bcf6837b1771572d396febc948170
Size
43.62 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argo-workflow-controller:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argo-workflow-controller:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argo-workflow-controller@sha256:317e2e9bb2e339ce258881595b6dcb572159ea66720b075eeaed8d3876c657ce |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argo-workflow-controller@sha256:02e7656993995ddb27033e931e3d64d9a32fca85eca645bb18f278a6891bb8d2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argo-workflow-controller@sha256:ae0d4f176c4ae14930ca847b5eafe057d4252c30af3968f283665bf950972085 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argo-workflow-controller@sha256:1faa237ac87ec786d1e89dea777cd3c0455c2edf18d97d1dc63816eb0a679cb7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argo-workflow-controller@sha256:0cbf3ab43883458d90b46ef55bd058a33111b244ede013d167ce0fac6bd78a99 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argo-workflow-controller@sha256:ecbaa3d276123902119947da32663c0f9a12806ac9437e4ec3b4d239b7c4a2bf |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argo-workflow-controller@sha256:e81b8feabd74ed3149646d2749cd73bc735adcbdaf5055ab9dc681fe8562e220 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argo-workflow-controller@sha256:2e6f5e7b68e1dbf9db4cdc21119e37d15bd5617f65a84d174a1e375a64d0b165 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argo-workflow-controller@sha256:89caceda511fb19264ee26c6ad28e22610e7ad24f7d09b53b82b90795fa7329d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argo-workflow-controller@sha256:acc63f24a7a87c155fd990903886da65b94ad795eba6e650e6a8f69b979c3455 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argo-workflow-controller@sha256:107ab64ce7d259348a7f39d757d9ad3170376741cf9492105f806c5aa633c096 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argo-workflow-controller@sha256:6fa905f74b96f93e4a5f59ce5a448e1c62f2f94a85ba275e8637004192f13302 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argo-workflow-controller@sha256:c3798c07153b4089b9683915370ae11b08415a9658ae5a72545a2215f92d75a4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argo-workflow-controller@sha256:3d8ca82370463dbdc557de335ef1eafcc9b9c06345d88464c4b3b55730ab9ef0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argo-workflow-controller@sha256:073ac61f8dfb90bf14b1ba85781828f40a672b18475cf5d52186233b7198f2e8 |