Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.90-alpine, 2.90-alpine3.24, 2.90.0-alpine, 2.90.0-alpine3.24

Index digest:

sha256:6aea149e245fbe03c98884cb306fad707d6c0aa12c74243653ba780f19a365f9

Manifest digest:

sha256:0d68fdb7f6e0973759271b9fb23940e79edf11885add73effebb1a397294fccc

Size

38.79 MB

Last pushed

1 day ago

Vulnerabilities

0
2
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:601c2afb0674a01d052b4632af07da855aa77e993e2608c532d9fa8d04c8f8bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:2acc59096d88c5de270ffcd23321a7817701cc2da2b2cb8d7c75f4089e9fede9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:3d28661720038ea203bf9615e49b1387e8195768ed3c10b307c42f7895742871
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:19fb6a5757ad3de24e0f02f44cfc705a5ab001765a0adb1e392e7e3fbec4f0fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:99f900d96bb7e8e4cabb8be9dcf579a9b4d7946d28714e505c882a5ec7b77b02
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:a61c52ffbfc687b17b6013de28b5ab8440a2886671c9b20c22b353fa6167b7bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:67ec0772c9cc201cd2f6105be2ce1286b7f49c951014dd9e5b749285fe4006df
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:3e732caf1be4d9e7cacf4cb8e4a451c70e08881c3f81ae4a7e0733cd1d38ccff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:eda9db9fcad915d1b62e8b3d781174101d78c6d08eb6f2a044a7bb9af7156c4a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:8591c037349a4eed70ef907c79866721d6ddbe1b92b1d645b5fb27a1f7a89d12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:2ef89664e1d6706f508a59cc2ae75ffc149e81d8631bbd1687bba01fec616249
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:b7f910363cae3e256a76f3039cd08d1aa041efc60e66a3c4564c559142a89e05
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:ceec246c2d241503474b924a42c05f71e0f806ea9a2380882e6a44876ed8509f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:16860dbd72c6d6a41323a6db5647c73af703dd0fba69094d04afdf02881fc8c1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:d649927971407d5bd2dd2dcbf67636a7cea01b5eca5edd0592e3eab798f2960f