Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.90-alpine-dev, 2.90-alpine3.24-dev, 2.90.0-alpine-dev, 2.90.0-alpine3.24-dev

Index digest:

sha256:796370419192549eff4f5e1c9b2c10adf9a5ac7223873092dd3ce8be93d4e80f

Manifest digest:

sha256:87980faff22aa4cd165ebcfab9440fa8ecca14cb1259f304645b2d89cf9ccb9a

Size

40.71 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:e6bf77eda03994d6f48c0203c18372c59d46760769aacf232ac9354f76df7831
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:0a9cd40b211a2d1a3767fec3c48949ca4fb8b6d51bd7ec5f191409ed8448d4b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:71e58677f7af983c98b156d2cc931e4c7eeae30f2599a51943f44a5d1fa7ff56
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:b4aaaac8f8b690f55623b605e05f87cdfbe7893c252623fba5ce4a4c0dda14f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:9a4e47399b255028f52403e105ff2271af4ae81bceb1ea1ec8348369afc32605
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:e648d01bdbb824f12bdb25bbc55d528de982664bc3a3d54bb4f089e1aa73e97f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:3455e0350e40aaf724cae9335a8fba6f77a5c6ca3f43c6da43c882159cd70fbb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:8ef705be5f9703dae100fb663eac0d7776506e97b7462a9cde4822352bb7642b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:ddcf74ad7cecf9263946e34049ca783872eb6d152956eb07cdbeb5d85b122d22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:9ff347f0415b6fbf522f6ea875f37dc0c776600a9e08b57277dc926c20b8ebcb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:94bbbd28f603b1ec256e4e1f3d16977d52bd9ac17946b71fd9a3313df9ce5f28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:2beebb0ff184d3c8c6a01cabbe21eb9cb6fd60ef32cdd930fd0ca50229d8cd52
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:fa7e2b50f666194f657aa3a98635b717772ea8cc6c45db38635e77a9420cb879
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:444ef09079822431de4673d98b3e78fd6ca3b46a3356aae56132846b294cdb0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:c0bee3ee9d6c4a2164515e94b9d4d63dc770d095252e757dd56954aa2ab32a9d