Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev

Index digest:

sha256:351025889b8c67cb5ce7cd2bea552ffa1f1709279d53f59337219b6aaaebbe62

Manifest digest:

sha256:1f4f9e0911ff0e942c24cc1a9f1052841259efaa712ea573c6717f82fede3083

Size

103.23 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:3df66cddd6344ca05aa9c19226d5a14a400e8ef1802ae61dda2bff26556ce8cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:73312551b93ca24cce9bcb9205796517773444c30679bf2ea0e4c3cda821a5a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:4d96f935bdba743a914c94aa94669c3458e0c471cdb731a1d53e9118007cf0a9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:010359b57e5473c2a2f337038bbb2f4f3b9aeca4e932bd24fd35f771daefd29a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:43d06e9063f49266373c15daac5128094fac96ba18de1622b1d00d22cfa0d047
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:2715ee997962cd4044bceee9169d9047997b9cb8eb3ea5fc4be01e4f76fa0774
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:135ed860a40f25550ad4f16891dad7dfc49b77f944d4d03c05783a5dc0d08aa4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:288c64d6f6ed9cc733c2b56d8a583115447c1d8099b4d30803835bc57883f79d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:d57671379ef9bbbd1a60d1a34a19358872d79792ecaaf1549e7c043030dc6703
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:bf318b136fe794ada8eacf529de3dd7b0a7b178d2953796e3db826859f8d024d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:06a1174a7766270aa43314d45f907785900123e849b644ba25df0db9aa1cad14
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:70a1f6beaba75ac8beb2b3cb42813b7965bd5eb2533a7000e6530fc91c0efc6a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:f1add81362b2b9425fddc99ea6f829f97a8e578bd2e2c3363f01b692d69f550e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:52bfa0d5055a6f852e51ec2c42e81cb6b2b37fa1669696ff2b498bca5629a87c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:c939b1aeb3b689d7b63603a41120325a4f52d3876eba28e2d7eca9cda2a29e8d