Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.19-debian-dev, 2.19-debian13-dev, 2.19-dev, 2.19.0-debian-dev, 2.19.0-debian13-dev, 2.19.0-dev

Index digest:

sha256:f0a1b6fd4f60052f31b058dd43633862905a8cb3da95bf9bb435d91fc6fbf1ac

Manifest digest:

sha256:c472058cb64104bc38330ce998739e8fee7386e16de096bcd6c3af930aba9c70

Size

45.99 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:08f8b92b070f26a87f054e6e24a9dc9f8bff9bfc410f0358c2d0332055e2f43e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:a6dcd768b569b5c27cccaa4df72f90010196012231bacec9e8eb4a93d5a7372f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:e4a8278928d7fe9560b11ca980cd35b4a8cf3cb10ef44796580bb71241dc97f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:d1b11f864ec3df3b6395560df29b68b7196daa25dd65ad6570d020d807fe3556
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:7fd483b456fa3d42ceff27f56c367681d4da118097bdb4a62f14debc4f245ff9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:dc46a569acd30f932cdb3b45ee448ed4abb6073c9ccc04dde20139a170e7274f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:e24dca44f80732787d57e1319bae5154de406b88c4215aa84247ad6575f23a17
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:50c3971b31c7cc7650165df04465309386c2fbb6f6b5775cda02a8d8f59129c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:4de278c7f23d3f7d1ce52c43b4170f5f58f0305c56864f1481da2be4293126bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:782c8daf4dcdd3d8fda62137f632d660bc23924423be52deb0ba3716275ab819
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:073d7cd5b8f65c1a44af7c9a1b322ba08aaf95930cfe3c4f1c6ad8941efd195d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:6010e32997acdd05b66835861592ac2a2a70ade980db1a684e077a03fdd906c5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:f5a7237e12321df87a692543a1d1aa67f989d3aa6a59c56447bc2a3eb5993f44
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:cff6100db006c47c9ae736e918cff444c41da4870f72d8a56bbb7fa279178f89
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:acf64cb79bcb2aaaff9b0b051e9c49ae9a606ef07e1681823b6a165374ffc4b7