Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:e767484e82bf10c698392053f58751da61b9b3f7e8bbfc1c745d1ce52ecc3e24

Manifest digest:

sha256:6d5ced9a78e3d9fde9f8d3793bbe524c2783537534e0b4e163676a1e286e63b8

Size

129.47 MB

Last pushed

4 days ago

Vulnerabilities

0
3
3
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:b723ca7777d5e54a4e891fc40b9e58e4a74cec1cc8dd4a8de0e03eae7ee41430
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:96825f75fba627952f8db2c21531def25dcc3462c7bd2aec8e3c39a9374a0c08
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:1aae10dc44aa08f80f9be33aaef15805b0579c856fc30a397fb4c6e283046d64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:8ae363af7019aa50925025b2dd1b41877a4d84cc459f7628c0398acd80cd8316
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:848ca2245302b41e3fa159a2219f0772943857b580a98895c3312536100fd7c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:1c9e6c7a7335a8c6cf70773ceb10b71becbbaf6f73f90469aad4f1a64227951f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:016f70ce64a5c6a7fc4ef8ab0d26f56c0b0f96c3148946b4944e855c3305298c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:f1c52ba39c757a2fcd44597a9cce03bc04850a6de9bfc7147c37bb9e171b5d10
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:66940acd1bb0996c04d90400f471c97d3b5ac6bba504a5679edcba15714a267e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:cf93d4749aafcb64e0092c67d7b4d85fafb42b715f158a780b9d7a12a579ae88
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:902ced1a055e1975d5683d6fd1477a6baaa78aa4069e0a22a67996eeefccddb7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:9b7e524c4daee556b002ba234794c387d04c09284edb1466de2c5436d524941e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:ddd80671d47e1375dc1ad75c931dbd533357c12096173803ef23e76e30589ec2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:5d3743b44a9e60cea8238435b7dfc8c98be81dcf2e84170a867367a3f50d3d64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:807e5f4b696bf54e81b117f7155ad574b74e7255c50ac28d32931a3ef4df83bf