dhi.io/couchdb
3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev
sha256:f260b1755dc4648003ce302af0247067d11fef3fdc7225f47b2e8962eee3472f
Manifest digest:sha256:6dc4e5020cd942803b4701f02b3af14d713e7bd2846e8bde7763aa6f1a8b8f6f
Size
103.22 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/couchdb:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/couchdb@sha256:5b8df6b0b7319510dbca49c9ff9ff337df02a441e40056baed024159e978b863 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/couchdb@sha256:3f86aae275c17faed4b973052c9f02b9d27bcace2b392adc0c1e5739f7fb3eb2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/couchdb@sha256:6a152d49f4f1c39153e04bb272780e0432ff9bd446329785581598c9ade276d7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/couchdb@sha256:184cf45689d2b3579dc2d8c4a7fa46106689f13bb36b51944c227f4410eaaf5b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/couchdb@sha256:5104aacf7d25a2d3f0f067e08c270a84621943e6c423fc7b7823913fc319f4b2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/couchdb@sha256:6065778c53d00b5c4f3c3ec5cc6374fae1dfa5a1e742c49987f6ccd108c8c57c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/couchdb@sha256:183cc746e405812d3644f147ef5a1911751c058d00872c467e89f9fe56beb9ba |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/couchdb@sha256:dc73c912501a88595ba256dbe50c2a26ef5c010d64d46581f0113a080b05e0ff |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/couchdb@sha256:ddbe78689f5d417e360720086e9a5d248c8ac00b748515fdcc41bea087a9e226 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/couchdb@sha256:4efe890c2b4bebd9194793c075a878bd667a380be0273d70da0efc4d29ca0293 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/couchdb@sha256:f386e579c2c229233177f27a6249253b32fa4f5cab7b313695b0f17bec201b43 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/couchdb@sha256:7825da30a871833d11ba9cff1c797e8c5649785c8b6cd7c4c5115995b22b344b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/couchdb@sha256:171db605bbaf101e8f9db0e09bd214593f91f26204cdac2f60142fd7e357f48e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/couchdb@sha256:872d6d5d037ab38aa111ed1ffebe9bc79ccb10cd708d46714b1602b343ad961a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/couchdb@sha256:ff7e13964356da9002c5365c90d2e7dff34461d31907d0d7343c153838ceaf98 |