Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.91-alpine, 2.91-alpine3.24, 2.91.0-alpine, 2.91.0-alpine3.24

Index digest:

sha256:6a7115e3da4517e4d7ba8a95765fa3118cc4b9e714cac5c9381e8c8ce4e6b0f0

Manifest digest:

sha256:99ed16aa9c1c42269bfe6bb4dee1ab4001bb61b555ef3f4b46ed38448bddd22b

Size

39.06 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:658a0ad42baf1e0e6331a41d48f55bff25060a570ac20fa0a5d8d886382e6c10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:1f9e26c266bd44c31ae1d50a91f13a4badd1df9cd75c2e114ffecbacdaa6471f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:d34d8bab4c715bc32d9aa77f89662ac8db8549b8a15781cbe51f8ecec85da472
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:9037d148adf35ca5bb145418ec206a542362f7164aae5280d1200225306a7aee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:62230bfa870cbd80583380909ea3146acdcb36a4b631980fafcab39e41b94b90
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:67ec8d15e28c0028910aa5a2ad96737e8c3502877113ec188967cd50c359b29c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:7128ed1ac0f4811bab121749280efad99200f78e272412470e5ebe9449fe4328
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:0fb5e0a2a3e652f3803af104a42776c105ffb50a42638db286ccc712f2a62945
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:ab45e8d95a5c3d8e4f6b865656e32e10e7076e7fade4283abd40831685ade4d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:072f8341a68cc35fd60198debf5a387b91b6823bd560005b57b2a9185fb2188b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:8f472c577d213a3314e8d89e538b73050e61828966e22aeca03d5f104252f301
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:40b764f2773185a7d133088821697526958f9c5829c1e9def418ba6d537e1edf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:0a52d4e75db0e8a6523b369aef68f7f2a2eec3d6a7625d17efc5fdae12ff87b6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:5113b60aa729dda35a4a723ff4fcb869fde2fc43bbc646360230fba39d556764
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:a8148602d1dd687f629772191a4b41d7fd50fbb90a80ba55372e092d920b524c