dhi.io/cassandra
5-debian-fips, 5-debian13-fips, 5-fips, 5.0-debian-fips, 5.0-debian13-fips, 5.0-fips, 5.0.9-debian-fips, 5.0.9-debian13-fips, 5.0.9-fips
sha256:3ed539f8a8716659b8c7fdb76150e8a05e75b13bb1c1ea82b04eb62db3c57a14
Manifest digest:sha256:e43adfcdda84e876a379b4381e6b7e05f5c2a3e7ff8823d737273e81b12aa2ff
Size
141.84 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cassandra:5-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cassandra:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cassandra@sha256:a3ae562403ac42922a9743af7ebfc95d170cebf12e120169c54bb09ba29db1f1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cassandra@sha256:beeac27a980f276e8eed3dfca91dbbc12fdc44b9ca6354c201f3b9c64a2c9b39 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cassandra@sha256:879cb30bf363bb792961f15e14148eab603b7a212bc8fa3e89643d6c1c77b89e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cassandra@sha256:5d0fa076ba83c9aeb6603c701ba0796281c3d0e97b916e41bb56615d8af8663d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cassandra@sha256:2929b2ee1dfe5749c7eb2f17f7035db53069b2ac9f0fc215f07b34119f3e210e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cassandra@sha256:0a2b4bcb535cb52f5fae71ca0bebd3ef3f9bc86c2c9d2af0d6f701bc66117ffb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cassandra@sha256:189a0e41175dbb4f31577d0fe532685feb0d35052d8dccf670069b90acdf760d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cassandra@sha256:18f9e9c020405aaaeb82f645be1a6f59b22ee914c73f574be8404c927e6d6dc7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cassandra@sha256:094498c7fb6bd3b8876844ebc4bf485414748f4b28888e59912481e604cd2be5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cassandra@sha256:b6a8ae8237832248fcff97f34a21c233d95003b9a9d2988e3c0f040fe26c53f9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cassandra@sha256:f6b4883c65ff3ebacc02819d97a0c36fe10a6b1c93cca57307d0a8e47c9c9a5c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cassandra@sha256:a74e26be4a0d14eeb89603c21fd416c9edfcf6105350b6108abe610c5d000a93 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cassandra@sha256:cdcebe02b630ee5721d900e59a36ba8183d9cc0e058e19deec55bdad060fe45a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cassandra@sha256:e431f7176fb48a104bd59d4b1644ad80d5434ec31455e0c1b74e6c615a9ae165 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cassandra@sha256:f9c992f5111b14f2ed20630a279f0e8b656a3b64116675d592c8e9dacd5c1a29 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cassandra@sha256:339c5318eb07a3a5e5ac5e03001e781acb2f8d16750dfcd1b4b24a0fc4a0c0fd |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cassandra@sha256:65d765d971761ab9bf3dd5ab2890c996d46628a76b21605a765163523e6f57db |