Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips, 2-alpine3.24-fips, 2.19-alpine-fips, 2.19-alpine3.24-fips, 2.19.0-alpine-fips, 2.19.0-alpine3.24-fips

Index digest:

sha256:68bc26b7d21858c2ed88341ff5093b97f9000e942e8a85d7a6e9c77d33500599

Manifest digest:

sha256:5cbc9a7a8e619ee163a211c870b3f4c9ced3ae1c2d6d1594a42200acf6a7a64b

Size

15.12 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:48789edc8cc550a822ab208dfafe9bc33bf2aa4e36b1982895b3bc862df331a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:572254bfd05346e405ecef8c54f5d20b906f8f5342582010d940d575e9288766
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cert-exporter@sha256:6e647ae85d0170429a91748c253b10134354b590c36f86233bb6b9ee2bcccf38
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:2b3005153f90beb43a83f4f0785106916b7da580539dc92dd3b274139bcc07e3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cert-exporter@sha256:cb959571c180b7df5a5b438c26f16d5763314ab25f809fbfacce18fa7836931a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:8563ef7174cbaaf3b897d5604fd5a9abd64ba22e86c9246598d8c2cc481533ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:2b245569916b5e9aed307490f7fbceebcf306c1e9299ef47228dc96fc91d15e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:e840ee65ef9ada3b34abd69d749384741b92d63b3a8f92020d20186a02422182
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:3c19d3d782bfe065a2ff437c71faa54f2c7b09eff4cd91b5f4c99cbfff1cc9dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:3fe82ceec1f9fb1da4524df32dccd0785dce86037dbc6866eb5b5fbd38553a45
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:03f458532da227344a5ac9a5149c5b5736f0e629d187ee238afb9512f8b9b141
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:e8d282f687ba9cf2e644f0007e480ed1ad25de8bc8101015fcd9d5ea4ba66589
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:50ebbfd13eb732ba0c5f0f378d2d4850bdae02c4bc30c063a69e9f7e2c7508f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:4386b4ad38c680a6315de69a9231ccdc9d9d0befe82c041fd3ab3c9759b4b076
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:00a303e17e4671395b38a6ff7e5eb992450d784bff5bd76578ae5c37f81d30b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:f17c9bfb31e1dadca58245f30ac020584e47ad1591280d5cbab7af8dce130130
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:16c571adbb860c58e45114c383187e72b0b5558a393f3517628845328b6f2414