Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.3.x

CIS
linux/amd64
debian 13
Tags:

3.3, 3.3-debian, 3.3-debian13, 3.3.15, 3.3.15-debian, 3.3.15-debian13

Index digest:

sha256:308be854d8bd7a3fd7dc22c4b889b930cd69f39c6cf1e2e251d0f9d7fb2b96da

Manifest digest:

sha256:315d98fb0bdc0007219e9297ebaa6211c3b12f6eb9a0477e64c7b38fc39961e5

Size

113.96 MB

Last pushed

10 hours ago

Vulnerabilities

4
14
2
14
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:c424c8de2be9e2a880e3bc188837b3f60e9faecc5dea98e69d782a14623b7f83
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:6a16a9128f9c8ccd0adf877f623e0520287a78cd648e7c61b516c0ab871bed51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:5fd6519c3f294fef458b2567b54187a3df8b9f5ae1c33bbced588cec62743000
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:2cfde4a12ff3a950d4980a2e21fbabec0d2576e83e19971199638f64e46c5f07
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:3aac9a65b70ec298a49406639850edc88240d513f6bf3996a222e30265fc2eea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:74c7e5c16d67b542afe430510deb5fd1bc8739dc61360703ab3b5d36be38eb93
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:08321abd88d3d143a9d15ed693d0c4caa4a8c3ad5f21b5def4d506ed7281b605
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:a42404f6d8398ffc0523bbad0e0329337ed4e39ab745d8b2d40ef071650c302a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:41e4916db7a93eeec10a99b54841e767567c2d50ec369f8b8862ce154c15e498
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:f5226572c758b0bb09befac6b35cd420683116dc1274c74848d590eaad5682a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:bdd97c6b1dfc3ee44374598eb770a314099792d2977912e4ea0b4c2e77fd0bce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:6e18b6bf8b617ee9480bea92fd59f4ab8766daac78b7aeae8def1a7a79da32f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:6d082dd38c422c2e1746eb7de3ed4f36afde32dd5ced58cbd7fc6622814855da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:7723c32f9f04661cdd7828f35e93aef620f6756d943851bd12e5a300dbc79482
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:32e64b69b9c8e12793a9377bc1424a274695fa12be6448311d22b2772a11ef97