dhi.io/argocd-image-updater
1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.1-debian-dev, 1.3.1-debian13-dev, 1.3.1-dev
sha256:6f71b2da36e388949be579a718e39bded14736796905c583c2ce518077ccb45b
Manifest digest:sha256:555de8741c76d8cecdd97fbfdd0b88250946f9a3b36cf151b6266514d45f5bb6
Size
131.15 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocd-image-updater:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocd-image-updater:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocd-image-updater@sha256:169673f2427072fe860bb26a9d2337394395adb19495593d9c4e17e87b642d50 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocd-image-updater@sha256:43989143584bd74bac4809de4126594c1da1413b87b9ec0f4c870a7390d5f9ed |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocd-image-updater@sha256:88b42e9eac79076b10d67ba2320b5b565e417ff3d5f11f1b8ef36899e2941b1f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocd-image-updater@sha256:a6bea629412c35944490a68a81e1beee01a8fb0a037fdd20d4a2fba6b5aa7088 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocd-image-updater@sha256:2eded3d60e142f4b23d9d2616b692067ae459a80e9b20a97e7f0823a3fd7de46 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocd-image-updater@sha256:cb86c8ac950df47615f7082834075cee6377324a3b03ef5f140b516aa2253bb8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocd-image-updater@sha256:1dbac1e0304999d70ec69186b7b1fae25b08cfb34fd40063c52a53e00733bc56 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocd-image-updater@sha256:1a527e692a7f0b7b912e0a0e87ae4d05c0048f0a402c46d7d569bf31b985c9bd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocd-image-updater@sha256:f5e7f09038844ba6e323e71c7040814779775aedf74c9e8dd3229b0e09e7d663 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocd-image-updater@sha256:d62357fadaead747a006e294f08df70cb51d6f57c1f2c5a3e606e3b1aac73b39 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocd-image-updater@sha256:8dff130406248ad4de4be77672081b00453e257e90c151149765f218ad3c7a75 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocd-image-updater@sha256:c41dca494e72f7712ed366079b212608f9d2446e94f2d65a7eb5ec373fe18c7f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocd-image-updater@sha256:8be827b63219cc0c83a2b99e8e95a2738999be9d97d8ab48a3b98729fb9de658 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocd-image-updater@sha256:3be7c3babe7f03dca2b53c0fb0bd64053a1c06dea20ba969b749c9c80693dd4d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocd-image-updater@sha256:16f0c7d566126ecbad203917ad238130b13496c1842f870b5d1777ca130a71de |