Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.90-alpine, 2.90-alpine3.24, 2.90.0-alpine, 2.90.0-alpine3.24

Index digest:

sha256:4926faea077eede15a9db39b1062ebf6370912fece1e106ea296d0cdfa0a7d8c

Manifest digest:

sha256:0e5646f85c570e789705a367e3833825221dfbd092ceca938f1b53ab214bbc6c

Size

38.80 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:8c30e0fc828fc2435226322c0cf4325cee9603e07d6cc8081641aaa7419cf013
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:fe5040177a24bf1942b07d1bbb9dbdd4a628ada38712a377a90a6be19a96f7a2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:4de8e43c846712e7f04c73091267e553d5e8ff1f0992a1a5f40103e44a5d339a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:890fca85e982fb40a0e91de142adbe6c4e0949762193adcddfdf155c2309f83a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:33796ac6579ee096174aa6777cb108f7d36d12f4e3d372f41a644308b153438d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:d000be620b6515c6b032c2fadb868eaaab4c404faa8b608e05384140b8403ae8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:d8195628f943a2ce7e427a2a12d5a040aa03ace540e2c1fa0b1922c073f1c7de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:8a84e81c9f67144c4fd871b7dc2c2968f8e3387df9f46c9a93fe70f65aa28367
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:f90c6bcda8d1f7ac23b081ba80622cab556f28c4691c7892cdb873d5d788e9c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:21ec80e37239528a0d8cd1c93c03361bf580f5305a5197b3be4d6db30d81602e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:95de7996cb875262433ab50b170c9abf98ab49df0f0adf1923a847102d55ae09
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:183721e7c54dc7182fbc605748f9e110aa5114fca082920db5f8f93cb1e9a3eb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:b9e470fdf962e27aaa7eb0a343fe6066b390b7bead52fe0443bba423f77644c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:d766f4a8cc5943232ad71af2e85a6d528a53b1f804f1421031d6c0f1b590dfe2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:01a60d1478e3b61e81c3349d70d43d2e4d4f0d1813bf4274621a6cef45892447