Sign inSign up
Argo CD Image Updater

dhi.io/argocd-image-updater

Argo CD Image Updater 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.1-debian-dev, 1.3.1-debian13-dev, 1.3.1-dev

Index digest:

sha256:6f71b2da36e388949be579a718e39bded14736796905c583c2ce518077ccb45b

Manifest digest:

sha256:555de8741c76d8cecdd97fbfdd0b88250946f9a3b36cf151b6266514d45f5bb6

Size

131.15 MB

Last pushed

4 hours ago

Vulnerabilities

2
4
0
12
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd-image-updater:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd-image-updater:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd-image-updater@sha256:169673f2427072fe860bb26a9d2337394395adb19495593d9c4e17e87b642d50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd-image-updater@sha256:43989143584bd74bac4809de4126594c1da1413b87b9ec0f4c870a7390d5f9ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd-image-updater@sha256:88b42e9eac79076b10d67ba2320b5b565e417ff3d5f11f1b8ef36899e2941b1f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd-image-updater@sha256:a6bea629412c35944490a68a81e1beee01a8fb0a037fdd20d4a2fba6b5aa7088
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd-image-updater@sha256:2eded3d60e142f4b23d9d2616b692067ae459a80e9b20a97e7f0823a3fd7de46
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd-image-updater@sha256:cb86c8ac950df47615f7082834075cee6377324a3b03ef5f140b516aa2253bb8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd-image-updater@sha256:1dbac1e0304999d70ec69186b7b1fae25b08cfb34fd40063c52a53e00733bc56
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd-image-updater@sha256:1a527e692a7f0b7b912e0a0e87ae4d05c0048f0a402c46d7d569bf31b985c9bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd-image-updater@sha256:f5e7f09038844ba6e323e71c7040814779775aedf74c9e8dd3229b0e09e7d663
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd-image-updater@sha256:d62357fadaead747a006e294f08df70cb51d6f57c1f2c5a3e606e3b1aac73b39
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd-image-updater@sha256:8dff130406248ad4de4be77672081b00453e257e90c151149765f218ad3c7a75
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd-image-updater@sha256:c41dca494e72f7712ed366079b212608f9d2446e94f2d65a7eb5ec373fe18c7f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd-image-updater@sha256:8be827b63219cc0c83a2b99e8e95a2738999be9d97d8ab48a3b98729fb9de658
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd-image-updater@sha256:3be7c3babe7f03dca2b53c0fb0bd64053a1c06dea20ba969b749c9c80693dd4d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd-image-updater@sha256:16f0c7d566126ecbad203917ad238130b13496c1842f870b5d1777ca130a71de