Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.90, 2.90-debian, 2.90-debian13, 2.90.0, 2.90.0-debian, 2.90.0-debian13

Index digest:

sha256:d139f0513d8b2c8417ce1297cdae1cce8f165448dae8f0d89c39e039ffecf220

Manifest digest:

sha256:dc4e650dd196b84faa1b2d8ff3525260e0f6693a2d8d136d54ef12583d9e174d

Size

37.43 MB

Last pushed

13 hours ago

Vulnerabilities

0
1
4
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:7de9b8b10e2d3fa91650186528a04d5fed31d6ae0ae7f17ce9e806f0fa65dedc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:266fd46f4e7a543d4743d08fc18645b3489c28d68377d92a3d711cbd6bec7c1e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:d3c33d51137a9f730d28259ebac7e79c262c6cc7a77a4870ce8b058882d2e394
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:823a4de9f0ba9a00c9bb7b7f34a4738ca37586780f6284d2175d33ddd1ff8f0a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:60d97e1a40628109ed605f2f191613e2f28b8fab35f808b959e75e63ddc3f8b5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:b9e28af14655b7523c9275d7cc06392366e048bb5609cef24ee5c4fe9189e01b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:4e56bd66bc3d18570b1e7695bb4d8330a64235beda0180f2ba86812dcd6700bc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:b8754380fd55eabcec1f6b38a3807a6c20d85366aea5db0cdaa04f6399d42bc3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:b3e9875a483285f156c041d4975317350b7d20357ab0455b5f203dfebbd680c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:203d4edf405d87bad32c135ca968be7d8c2a12c256bb532aa71d51d6bdcef9cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:cfa30ad3f36eea688c1acea598cd814c7d9fd134d2dbece92eb42586f68680ef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:702ba83c15b52d40af9e7ee74c4e5a693bc235077940021026262a0b1e9242fe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:ad860f84b990f1153afe249449e1cebbd8bd79640c6c9414e35e62d124212ab8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:eab420c960938d3e3c2f51ada0083b9d97afa937dd9fa5945700d98327251fac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:4b55ae7f1fb5ff15db53997fb98a27408c4b651e7e7c9302895aba7595291e70