Sign inSign up
Argo CD Image Updater

dhi.io/argocd-image-updater

Argo CD Image Updater 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.3, 1.3-debian, 1.3-debian13, 1.3.1, 1.3.1-debian, 1.3.1-debian13

Index digest:

sha256:4f1a96d6c44515f1aa96fcfa00df788cf0a6bf71c7a4c6c696a05c7583db49f5

Manifest digest:

sha256:08c3a435b413f126d1136a839ac98f2c02ecc14748b1715447a10f38fb4674c4

Size

121.50 MB

Last pushed

12 hours ago

Vulnerabilities

2
4
0
12
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd-image-updater:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd-image-updater:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd-image-updater@sha256:4bba7f9a852ca42e285a6a5f2a469d308dbf8ebd0961ff84b638b1abcadbb137
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd-image-updater@sha256:9c768bd20e7dd5d047056154c07ff764f44d87427aa15bd402d7a581d5b10794
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd-image-updater@sha256:0d3c09f726c58b840e53162121cac67d22e7efd24d7a60dff2908e6f1ae2103e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd-image-updater@sha256:b23ca58945fc5273c7c7f09505cd5936b7b9c01f091f6e486e19adb9386dbc02
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd-image-updater@sha256:17e6a9b9933d735282a44d3b5c89d6d93e730a1e0a46233663a5e1f63786153f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd-image-updater@sha256:6d33d75af76cf717ef2c3428a3632e5f4a0b2bc9caaf57cd7ee4c1de5448dd90
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd-image-updater@sha256:f07aca9101a6a081390abb24c8dfad307894fc6487fea08686cb29bdbba84c5f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd-image-updater@sha256:0ee49ef3efcdfb0f56b8cb41ae8da972242724f559340cf945201554041d6356
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd-image-updater@sha256:b4691c75c5e576210b05210e71e08bd1f418c156618761c5f4917941a5684d6a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd-image-updater@sha256:5a7052ae1d403475253583b15e605732303660db0c601cc2e95ce1ea984ce78c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd-image-updater@sha256:97f0c085f86056203dcd510b517676d0052edd7eef16fa1bd725169a60f502fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd-image-updater@sha256:1357927e5e90895addcf3bdcd3fee55196346da5d6b910eff0fd72131e261ff2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd-image-updater@sha256:92df968c00ea8671b3a99978e4c291e0ebbc8588997455b9507866de6748cee5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd-image-updater@sha256:bb2026d596debc33dc995dd547d77915e1819b9f461c275551437dea7d8a1f66
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd-image-updater@sha256:1e6e5022a213eae70a8c90875ba98e96695751644a5bac004abd481962d6b3bc