Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.91, 2.91-debian, 2.91-debian13, 2.91.0, 2.91.0-debian, 2.91.0-debian13

Index digest:

sha256:2dc6203b6f05fde1a00096934de84b29f011c43e92d7fad60aa6b8c5bac89bf1

Manifest digest:

sha256:94982272e4b5067707fd935e5a66bf878955cdc6140e35bdf7e108c24bcd6ccd

Size

37.71 MB

Last pushed

23 hours ago

Vulnerabilities

0
1
4
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:0339cffdd1ab94ad260deb2fe210d092a17f82d165d5f9da2be90e51db92fe40
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:ba0a5ba3e833638ad8f1bbb53cf7298664a10c7d83913ed556771a8e00629e6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:326a1f51e420cd329e076ad301542b067d6a380aabbc16ce45f20397235be7e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:d9713d19eddb8b16c53d3cac88dd9eeb22673822682426d6887259566434d7ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:1f49ac9d0980fc1d510dc4b2c9c3ebf7747bc280615310be05909c807792b8c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:70314c55ce34a18f276180148e33a686c076a6cd54bce707e6756ee75e6777c2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:97f89ed908991ff92a030a7c97e6ba9811161dda17546d3d56306fcc01079ce9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:fdd02c761dd4f66c3788776fc48a4be4e626667c16c577914747e36b0579eba0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:6987d9388ccc210b538380e15f09194206107e8f2a3afd6c364db121e78b8bf8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:ddd3184c296e6fddf24dbd5261a3bc9615e17429a0e3a8e044529cad7f5e073c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:5aed82b2a42265d13e456ecf14da28480fcae942bd8a7cf65865a515b39b66b0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:be8052c78caf8b0130e7e4a2cf5a2db810b7a2d44eb89b93b5bd1bda1e490e51
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:a2c456c20d05074b2022974798b70b45056e6eef7c2beacf5ba9227795633ed7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:9fc733473393246ed1c2d7f53c53baf11ef3353d4a2de1bf8d84a0688a7e5ea5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:ac6a908e5bb8e7b696f0f1ac86ed94760962fa97afca347f847f4be92b3626b2