dhi.io/azure-cli
2, 2-debian, 2-debian13, 2.91, 2.91-debian, 2.91-debian13, 2.91.0, 2.91.0-debian, 2.91.0-debian13
sha256:aa1713163feecc4d84be45b784cb54c62eb1d1eadc69b04bedf54b086d860463
Manifest digest:sha256:83d33f4b5b0f175a21b3f9cdfd2f5c83f69da19dd9947207532dfd693f4c8b50
Size
37.71 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/azure-cli:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/azure-cli:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/azure-cli@sha256:88d3ac1b449ca1a0506acf035fdfe25204e90535245ccc16e3bdd853e5c9c96e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/azure-cli@sha256:c0a3557ce2968edcd21910da650c25dc737838b6b4af5b72cc2bcfe870097498 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/azure-cli@sha256:5d2b67a6b70f98a5f4554ad8c3ea59ce2282d910ee040cab790a99570ed3df4e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/azure-cli@sha256:861337e5aa4ef543e5d9d4fd329e6abff307004a70e4f71aee3f06eb831ec613 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/azure-cli@sha256:41fe97a5c97df2279239a6a949ddf41e79c3c858db8f17ed0702ec8f5d0bebea |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/azure-cli@sha256:e0bf860b4f433ac1643605c11c4fa9823e30840606c4b812527e69683f425681 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/azure-cli@sha256:184bb0e55893d903d0b5ade8dcc3e21d2c8e9edde623348d6584ba22e42fd6e8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/azure-cli@sha256:77bc8955f84387851c3059db27707e21cccc5ada5b96d7ae41b16daf6f4e1081 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/azure-cli@sha256:182f955b46f6ffd6fc20e82ff36b2a222313cc3414e02c73d6471d5233a67d6e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/azure-cli@sha256:9e93f7223465d91af5d7826ffc82b7f04c990b932e16b5ef4567f668c04dc230 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/azure-cli@sha256:c30b2e1f43ccc592316ecd75a2c51cd762816b5c50a29451ca50e403b0fac166 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/azure-cli@sha256:4409626025a1ffdebc85e1b79456bc84adee377526e1c47b07886ebc92dbe635 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/azure-cli@sha256:83ab1e1486746c13775434de8031aa03c8b3579e9d066ab7a238b8faa904749f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/azure-cli@sha256:124cdafbb3dcd6543ad320a2249d86302b4397064898292a8ae1e88a0e72d572 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/azure-cli@sha256:797075f6e242cd64062302e2e8d15ebcd2d76bbe6739efdb202baac51172c88a |