dhi.io/azure-cli
2-debian-dev, 2-debian13-dev, 2-dev, 2.90-debian-dev, 2.90-debian13-dev, 2.90-dev, 2.90.0-debian-dev, 2.90.0-debian13-dev, 2.90.0-dev
sha256:3abd2b4f6a258f4cea55eaeca4b84329dbeee11757eb0145e26bb3fd747755f6
Manifest digest:sha256:0bd86edf5bad8ed720b38b136e7c6f257035ed09cb6134908e56a486e34aaa65
Size
51.08 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/azure-cli:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/azure-cli:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/azure-cli@sha256:cee9ab48e281379985be041975e63165da637432c1258928ba7a3995b9e35bbf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/azure-cli@sha256:72f72aedfdabe4502bc86616e836ebbd92702747f7cc7eaecdf3851df2689f92 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/azure-cli@sha256:e3a9479e0667a0ccc36ddeb452a0e31ffff0731e4b6384ce8e76c45a7bdec1a5 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/azure-cli@sha256:a37c1c0ee7c6d9afc18b94ee74efaf7b41242dc79f4231dd3baadb76e9cfe9e8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/azure-cli@sha256:53970a525df7eb1ecab688990f6eff00101a024068ab61183473251f2a74d633 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/azure-cli@sha256:b8a8cea83da31be7a66668af35b2982451e2f81afe477aaa671db40521f52a6e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/azure-cli@sha256:9d25dcffa76077ae4abf53d12bebe68692b7897159bda72638e88c69a56c290c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/azure-cli@sha256:456ae39b53328e8d0582ceb9c6990f5336bbc4a82265e002508a2a859ddddb5d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/azure-cli@sha256:b2b85e9032403440192e0eb003421c96981c9be86b8c6fa8d81633d9a1f5bf9c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/azure-cli@sha256:cb3477913841746852fadb2d1410d92e9b02bbb9e971e6edc5c5edd8178a079b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/azure-cli@sha256:e2612e0c30b8f2a11f11efdbeea2210c39212cfbe40d63efa475d35d521895b7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/azure-cli@sha256:67d2736889b7d5ce0d3799cc1a883585270ec2ec8d417c047865b17cc3882715 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/azure-cli@sha256:0de740ef037a0ef41f0196f6e80ec4409f061dd95d1dc02e91a97ef0ed279b84 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/azure-cli@sha256:19a793bfcfbb7284f63c70cdd9c9bac737c18303340667f2e5976b2964c6b689 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/azure-cli@sha256:a2f64aacb0a3e9b93d4ac195f88da9ab6ae4298e25c19ab8550c6cc461702975 |