Sign inSign up
Argo CD Image Updater

dhi.io/argocd-image-updater

Argo CD Image Updater 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.3, 1.3-debian, 1.3-debian13, 1.3.0, 1.3.0-debian, 1.3.0-debian13

Index digest:

sha256:9b079dd115ebc5a71f664ba991141fbb2c0c571a61e8e57ee3b71a38c6fbc0f1

Manifest digest:

sha256:3fdc7d6c460c01727d223ea52ded66b77e0a75b1029b5e34bd934dcf9e8c460a

Size

121.67 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
12
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd-image-updater:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd-image-updater:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd-image-updater@sha256:687a7378adbf9b900a4aac2795137d16abbe55a3616840a6d22a76ae33913a18
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd-image-updater@sha256:9040b344cb9fc0c4e18c50796f2c014f0310072283b9ce9e8a5a72a4d0a58f0a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd-image-updater@sha256:fbbeb5d6db17936250e97563add5112474eac5d17098be87ba308643288b968f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd-image-updater@sha256:b586f570a6fb9cec26d36060fa410f5ecc3b35cf003f33922cb1c35d68b80004
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd-image-updater@sha256:e130358958a206b07d42be63800bdcf57f7f0cfb8542fa15969e73538adcdf24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd-image-updater@sha256:393390552445f106753abeabb39513ad9ae89311fa0ab6f7d27124bd984dedb4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd-image-updater@sha256:d2294384269d924f62092ba3782b3a6027ce6af51b8d61e7abbf21d9440f4f65
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd-image-updater@sha256:170278df9e78be767684cafa0ef629d7fa404882ed504a9be68cb81095096ef2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd-image-updater@sha256:a919d687a856f473cf75d9d749fa3b0ee7bf4a12946f0a88b4f3ff188e6991d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd-image-updater@sha256:73d57a80af4415c1ad79688e76ca1b7972a15eeec739d30cb1b00da61e4ec212
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd-image-updater@sha256:d94bfb122167add34f6c5bc7792b52de85d711aa1eb384133f83521f85917d2e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd-image-updater@sha256:951409c0d28c20108a51dd4a24ee96bd965edc7ba4040aea8aa5693c960a7152
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd-image-updater@sha256:8c203841de9796b1f7a4cbaca352103715f0779d0247af6efb136dfd22a4c1c0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd-image-updater@sha256:d707ead11f296f118f78673b27a69d8fc26b9f883d8a9dbd0312161318ee5479
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd-image-updater@sha256:1eea1c799a3db1a707eb82b1d97a0cd2e97dfd13d9020ca1ced6d409e4e733b5