Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.90-debian-fips-dev, 2.90-debian13-fips-dev, 2.90-fips-dev, 2.90.0-debian-fips-dev, 2.90.0-debian13-fips-dev, 2.90.0-fips-dev

Index digest:

sha256:d31375e91adaa1aca3e6a087d1ec585cccab6520de8a24cdb6dde8ed74eb16e8

Manifest digest:

sha256:3c685b366f2cb9ea3a5343cc513397d0b058e7af6a24a26cbe39e278ce83c77e

Size

51.81 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
5
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:cd901007c407571380b6868b05cb0156db697a1ed0e9d2c2f3a08c1e355a6355
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:41f5df48827bb970e886c60ad439a46f758c4cfbcbccccea60b45ad223966d79
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/azure-cli@sha256:87422ac78492ae11036f10cd697775a1464b62cf8c517d062fa436cfeeebdb94
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:6ba2810009187fee17cae00fc29b5efd4935d32d71181275c073bd3d363c2c18
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/azure-cli@sha256:63b9c6c72b5fc40c192507a19032154caad34b7cdb6fda0f0572d28e7dfaf3ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:ad2e1cb5e44d6432f6661374813c5188884cf1f1791b02b911c7ad260dd212ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:8b4c5039e5762b3062b0a7aed33aa636da56832d54915c2a175a1deeaad0070d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:98d87c7830cf797afb94eab7bef2a876893379d7c5ad6af7fc38f48fffe30ad8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:c2f85a16b4015cb3f4006dcd327c82b1af8876552af8f0c3e1c592c0c590572e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:fedb60398e0eabd8f925fe09bfc4cd721c7a0baef26e4c18d89690d83117ded2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:02f727285f5e236ebdec95d23257870f2680c63ed631958ab7876df6888b012d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:a2bb7d08b134c177077681a7f9e412befa2d92bcebd2cdf0d8f400bae05b6812
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:74125f47bcdb6b5c6a1a30e1837edb8b14bc669cd05f5af71a26c88df43bb89a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:c33f19cd4c1679af7bf0066397a8b5222caad8d604f44267af2ee2cf0bbc43ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:74461d2168071d4902aaebb595520d28d6bb8f6307690a9dea4aa93709b9f9d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:e3e8704d607616f6d7061efcc40ec1c13a1feb8bcd50866357b50a2e8ed0ed21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:56aec074abe7049a2c90d66e3bc4bed4624ffbf721916bd232eef338721f5855