Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev

Index digest:

sha256:44ac27aea09aeb402a73eb93e1c021cca8bbc57d8d4a7cc4f546c841afb9f23d

Manifest digest:

sha256:9fcb3e6b1104b6e72a75815fe3047b9fbc6dd87dfe4b729ceec37be462cec213

Size

103.23 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:d2353498837161943ece6b7b6debb51f3a974bc9d6334390a2c317a228b7b111
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:486d53aa26ca18784e306b12a279b6a07aab22ad5599f97b1f286860a2bb13b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:e432c3ec137fd6c65ef7765ef4b6685568c08d0b4589e9348e1fa84bacbeac4e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:cc79e0243c13fef1a93bd133b06d159f80f816328c6a495d97caeeff7228d082
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:144c316028c093a41b1c2d1ea6838d6f026c5b71db0d9f7f5a9d5805cf7ee788
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:539bccd5680d796b862c102bac5a31f4bf0fc9c17c3addfb1fd62aa36bab5efd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:e659bf29c5457fc5f22baa40c6141596d9f4b502a8700bc1d27543a9f79449a1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:04e6604ab32f2c45912d986de60255df8345daad26ee161ea1b2f918a5283bcc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:8aa2b457c7f0fcb314ea3ef41bd0fdc18889d4a36dab9b53489f3189249465cc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:334683bf21502e6a3a1a324aeaf026e2b53c267c7a583ebf454d26828bf4e852
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:6a3f96beaaa27097549406f04551e4b30229ea91a06400f1393e1657fdd618de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:1ae285b91c55248737fa9f668db000a35b39856f4d27a132878918a764dc5411
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:e800a8cc4dcd1442f0f03c8c5dd5e512ad1a28cba4606f0a4ffb070967a592e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:2ac87283f86e6f81edfa2e9fbe419fb82558d4f04820ab69d97b9a2217ebdca4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:6d40b0cddc40ffac1191ee86dd5f06ed16a0a9b8e36b877167d8865aee317284