dhi.io/argocd
3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.4-debian-fips, 3.5.4-debian13-fips, 3.5.4-fips
sha256:d39147d27f17b489d756d3a28ebc5e358a916600b8a00ce63c3a096fc0e9b8bf
Manifest digest:sha256:458652058b378764905ba49602e4e1e6927b2a50e5164bab37bad33eb7332bb7
Size
116.11 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocd:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocd:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocd@sha256:7cb442e8a6673838978b896b12108e020af6226bfff40b4749ba71742bb52b82 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocd@sha256:814a487e4ee554a7e32afad1750aea15bb5e7d024669f2ea232796553819711e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocd@sha256:ef495a40066b23da1bd89530757ca82b3508f1d3624a13fe5c7317e1bcb55e21 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocd@sha256:934172b811ab6b61a4cd0661a4ce0b07aaaee3c9a1b223b5553c86fb0274b6de |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocd@sha256:e2da419dd9b6e0a3500bb76d7413710a2d10e21981115bb645f039dfd64e6559 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocd@sha256:19aecf6d44dd7deacf1fea6603e1f58a52eff76a04e70bdc4af23596c1b39094 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocd@sha256:d7fd1e3173bb1f5527da81ce70e3118dc155512e906525ef9117b5d241e94933 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocd@sha256:5c0a8669189b2514c2b610a3482a7cb73f4fc08b116a631d1ad95df66dfcf6f5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocd@sha256:81b9ab00a01d56b7a0971874318f5e0fb1df5b94791ea34d1a2b1b854a0bd782 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocd@sha256:8ee88fa2b885219def4626c1653dfc49466d2a52fcadf5bcb41b0eaa972db7a0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocd@sha256:df7940db57a3bca5a2e5c8a50db1bedcd7ced475ab62aca549751a19b325c64a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocd@sha256:57f637b6ff9062cb9c78321bd85a4f804e08f0d5c0f5abc1e095e9ee4b1f24de |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocd@sha256:98a11dbedcf3fcdfaf13f08afa025a925bd8ce166573699c435c3b85af67b516 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocd@sha256:116513fc51cb5d83d311f8082792baed3fc158267ce85f61e71a28b9af0714c3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocd@sha256:3e1c7c365c3ddcfb67d6c8f0b6b097abf6240cb741ba63e481c442a8723a96da |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocd@sha256:808db17538bc1901c732a1f56fc5e26f5e32fd3d8ece57ca318b6da02dec675a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocd@sha256:7c79dd6f0392444881bfb96dd59c767eca962edfc6667f09fc7866365ee16408 |