Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.90-debian-fips-dev, 2.90-debian13-fips-dev, 2.90-fips-dev, 2.90.0-debian-fips-dev, 2.90.0-debian13-fips-dev, 2.90.0-fips-dev

Index digest:

sha256:5a8d6f55fb717761e2572292a08fd151a4476b8a3bfbb4572806b3fd06159cbd

Manifest digest:

sha256:367f322deef0f98af905f429ef5b8c7e2b52f7373a173238ae0067308de8c51c

Size

51.83 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:fda23cde22608d2ba5990cc624f524b3ce389265b970ff332c5f775f1d5da0ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:4c47471540262072a8ff62734a60b33237e8aba41a7f6b86133314aa65afde23
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/azure-cli@sha256:5abaa023d57b60275bf3612cc29ac1407897fbbdf48e5e21809585ac8fdc8df7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:b3f993407d7d99069fdde9081aa0edf3941ebf91630815f0b44edfee0eccb117
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/azure-cli@sha256:69568617ae835449a6304e04aa38cef8fcb42ed4fc8197d94f3ce9275d64fdec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:c31299d8c4fb87354a803a5b96f98c8fb9adc6f2aab7b7161803f12f5b24661d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:40041f8cfa737f664811ba01ddb34117d913d8ce0db0a8646aa4cd359d593b21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:95317af48ae2b38c7c4e4a5e56ed8da3b80ff87381da2f157be76a42849074e7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:1a1d1b773d696f80c3d0ae1594c5fc9ba5221af5800a6f0b93f8176bec83a8a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:db0da8017f94f827dff5d4836fb41d9dc46574adfee7c0c30c1cdcc75d872f63
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:bc601b22b0f5dbac286de20cfedc246830f35a92cdedc6ef9b9a44a6f747477f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:10d61287a057593221610902b17c1ce01c4fb02e050fd2315cfbb05b999d1706
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:e5e918571bee675a3ac9e43523901e9ad467337523c9a189b925d61067ae395e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:c2216496e8b71d095857d7050af74eb25da0fa9c8ea582f8f3c43a591f5f5636
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:eff481c95a5968488ecd562f5759f49d57a5409417ec52351248ee198e1f521b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:5ca591b17ce5a9955a211a966f14d4ec6d22731c61c3e27d054841b71af4e26e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:358b62a88b094dbb57da26c9364d44d29aab4e7587bdc352e388640230a84898