dhi.io/couchdb
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.5-debian-fips-dev, 3.5-debian13-fips-dev, 3.5-fips-dev, 3.5.2-debian-fips-dev, 3.5.2-debian13-fips-dev, 3.5.2-fips-dev
sha256:bd3f4b25ff1c61b5504b7d0723ecd6bd51c1b21a45e2923ddd7614cf7b2fc567
Manifest digest:sha256:ac05e01ac09ec4dfc9d87c2e31b8cd4a36acc75e08757795f7cfbb1f384024e0
Size
103.95 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/couchdb:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/couchdb:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/couchdb@sha256:c6bd38d13a17714578f9161286b14715b6c696da09a1aa46c8eca7489fc23596 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/couchdb@sha256:dd8276c6dbbee2a1db6dd723965b717f39b07e13deeed3e422b2c3d68e99fdfa |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/couchdb@sha256:3fe3160aab43df6ebb37d670b2d11722c491e44e1f54e0a23aba574a7e9ac29d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/couchdb@sha256:e839f9ce6d95fb200807dbc27563cdff17e5457a88724566b91aa1c0089b863b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/couchdb@sha256:8323bffda9d3632055645b5b9fdf227aa98bc035719be1fe7cf842633af645c8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/couchdb@sha256:321ef27be40cdf4933e9842b13487c8656e0cbb00bf077ee01e8764d43d579b6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/couchdb@sha256:f263bb4861a43e2f77a47af566153a4e5a2a1a3b41d9426623d613510553666e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/couchdb@sha256:4730de1ac47243b9af562425fcc0c990d7e5accd1e962afa5303464f47507f50 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/couchdb@sha256:6b022992b68d4e215deb52cf0113592980de56ebf188b5364bc22cbe46b2aca0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/couchdb@sha256:d3b158a87946c8aa4c5de72b1e7726ac078f980f316069f330d44ae032a0cfeb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/couchdb@sha256:e00598c69b1fdd5c7944dec97794b2ee2da4710dc5d0242b1bacda7e6bcb7410 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/couchdb@sha256:61d6a239f7d349898c70f61ecd8fd92b9dd30f90210aeca654cd157628cb7db0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/couchdb@sha256:e0b0fd6ab7c9a75a7a2194b227619494376fe4f3dee9258ba22aa754e95d702e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/couchdb@sha256:745a1961b8ef1415000db3ee0237db0451a80599876f7a483dd1137028414771 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/couchdb@sha256:b8bc288c03759646aa9a4c472ee3bb64e2ec7fe2c329d853230eb60e556e061e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/couchdb@sha256:34e14afc69c9c55152be7d1de314f233fc1dccf8ef026ef265f5a60a0c5e4fd1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/couchdb@sha256:21c650ac2cc6880efed08729c375425066d72adc96047f04f3457024191e12ba |