Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 4.1.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.1, 4.1-debian, 4.1-debian13, 4.1.4, 4.1.4-debian, 4.1.4-debian13

Index digest:

sha256:7e93612591dac117aeb2926203283f3fa6c4888361acf19855ead5983152f1ea

Manifest digest:

sha256:0ba9c2680ef38fa18ec36e4c33c911a721e4bd5457d2f123a01014350bbec207

Size

74.47 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:7cc5834c5d829cfa2fb09a52d66526c9aaa5557598e8f97a936951a807f47673
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:461ebeac3866633856dfd231788cc8a18f7db06d9e6ce12437818155468916cf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:13081273e3022de222fe5475a0f05d837bf739f02a3f569bd6a7b9c5e440b490
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:52089ea04399d37a2eb2667c032034adfd50ece93649c0b77e5fe8e95032eb4a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:b4a38c2c8219b6c87dde46e683dffee260fe4c191193402e05e488b97d628bc9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:996c9c09f6ecaada107a6d1ab9cf0dadf66cf6ea0e13b605642c328784c15c23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:591da2ba4c2d4296d0d6b8a5343a3032c9a5935e55f6c4145c7bb6b1db8f1ea7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:908440aebd7a062ab73957307b391422b45841da84cb04b50ed3b55de9a949d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:aa1fe1f68ef15401a06769f8005e5c311ad93d50daee2a560a5b427726ddcb03
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:3b6d6a6acfd1e1a63735cd7eea1955c7ea755e263e1bfc27a2ccd9feadf16bcb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:8d9cc799da77bfde53918c706eb86ceb6230e76937087d04ae0e1ad8429f0297
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:e319d0892847e6a0fec35de99d066aaa2666bc96fb775611ffcb73829bdf0919
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:d5293503881db3be6d24ab7b9d0b47bbda08a75d1467d4e924c3b4a261559d51
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:9fc9e1b5b52e97898e2f9d33b52ebddc9fc0f75bf794b3b93cd783dc5026be61
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:d5e3002069d18b220db6fd9a754793cda763d48e76fb891e0c747af695a4a6b2