Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.3-debian-fips, 3.5.3-debian13-fips, 3.5.3-fips

Index digest:

sha256:05f5fe7b43502480518455c0f15f84963b4d49b8835e65b4fb90f9fa5efe8cd2

Manifest digest:

sha256:4617b728048ae47bd271bcb1d0295e935ad2bc77804d5fb5be6c962d9f3013ab

Size

116.12 MB

Last pushed

22 hours ago

Vulnerabilities

0
2
2
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:9420468320a7a297b03bf0767b88b7ab425b53c45bf190c6f60a2840a413b9cd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:1c4b66bbdf39f29a7837559f40f47fce009fd7ab47f6a43fcf6557b7c1924ccd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocd@sha256:1d7d47fe0d8200f692f126e31eb1393a8f8260e0f097741286197f3b52661985
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:d292588c775a0f753dd84a6cf17e43d0dbcd4d67282c5e301c22d2b03c19accb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocd@sha256:c98c72f2e3b532202f002255c25e031a5e7597838aaabeded773d33c601adfba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:167d2d1a833e017e3f78b11131a11882d4c4cca83828a76393ea02c52d707761
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:0a206e3aa6b57df7d5c433bb32f29d5149d31ef08b81ee79802a64a5d6151bc1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:d51883de81f3397c8f36e000c5ecd68402e7d02b8f55f8de9951938e5b62e004
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:57fd2fce40c378c4b54c81995759a6890337ea27d28c62cadc10596fd9ec845e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:5f548880506703e8dbc182d1139e23672548e9846ac60c876cb8db9226b7ee74
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:8112e82a30f29c9b2132524bd35e094c9c700acf9d082f5923923665e159ab47
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:5d08dc1dd3b367ddcef4d485258ee60b48d432c2002780e487e0d6233842fd19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:889d625286ccc1354026756e8c8e51acdbe3084ae89918f760835ce9b1b05e60
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:acdb7c31269f02acecd17a2960d623276775ccfd1497b7b7944b3789cff8f4bc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:5d314504f6af0cfafa3f3ad2a40aaf9efc9edae68da9647e934bcf316334bfff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:3712dc3e732532505595c6bddc8aa4c7716e5410a7319e8706cd8a09f7acde90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:afc41afa1e22cc547520938bc312b3356ff13f1d2f1173d07f631f5632accfbe