Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.5.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.5, 3.5-debian, 3.5-debian13, 3.5.3, 3.5.3-debian, 3.5.3-debian13

Index digest:

sha256:cde413742f55fa09bcb94b29a35e27bca0ec4982bf07b1208c0fbb0f6d5197a5

Manifest digest:

sha256:1a4073a1df0bc91c61fe82e44902b99f83285053da9be309a690c9c29ce7694e

Size

114.01 MB

Last pushed

1 day ago

Vulnerabilities

0
2
2
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:6cb5757a2cfa810b6772251bd05e911f14c1bb7f331d2340cdfb7a1e45d81445
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:1b7deb15f79eca62a578c7962197ec22c644c9253f72228c5bd4f5d50eeb11e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:d84a53b32b1061116996403ebd95ff9a1a40f1ece17a9a51666508f2f847b03a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:f2f7bfa35054a8f0d3a6520e5f18fddbc3746965780f792ce6ff8dab4bd8b673
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:fb2657f2e630eca975d2b66a81737d84bc8eb4684f7430c9d740ab8b713d7d25
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:9046b6a64a46cad2fd595dda027f683bb8b4a3759f7c9a4a23a5e65e354388f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:79b39b23b6184a8deffa388caa3d6f61a341f6d319ffd74a11403b219c885c36
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:7797bd3274dd7bc6f8ae70e6b8d62b317d96aaf62b2520f51170ab0decb7d4ca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:776b5211851a33cc282782ad1e980e70038eb00b76f4b33f82206229131c16ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:2e6941901692c69bdd22a84801262b18303ddf4983d524aa29d0c7234d011bf7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:b5416eee1a4c7b32945e1b3238722bdc4b6421334808023c5ebd56017c24074e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:a1fe2dbe4cfc7c4fd09e0be8e06e3593caaa53889014877a01ed479e62686626
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:51865a9b4c61213de5d2d93741ef9f8f35ee29d8947c3779f220a7814ebc2e72
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:1d53c36b3c3736e9291eb4b44f6fcf286ff2425e1f28f878b930467b938577f9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:9469c8fa2b04334b262a62140afd21a1308e56c5607c361ac160736ab53b96b4