Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:b863497309f95df9fb9db99338fed3048433c64f7341713782fca2b80110866e

Manifest digest:

sha256:27efe621a756906311132be6c1bee296ea7001a291f01131e7579981b86d30eb

Size

129.93 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:d0fb47a0434e21fa8d390d144cd4cb072812f44871f63da914595d5c750d36c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:097369eaab1d363af040f30b353eee6b194d9ac3618786c565e8dd9ac8011528
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-daprd@sha256:bcda9291dc5fd3fbbc02ea78b84494bd0272eb5bac5f36ce288169a106fe669f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:84b29a9197a85a029f01a373c0cb820a2263746062f123b7bea59728a297851d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-daprd@sha256:365ecad03bdda969cb109d9f7689609b7bcfac1f8023d4162ab75eefc4346ded
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:64664bb2b9efdcb886ec3b40384b554bc2aff9c65fb735c02cb7b1b7851c04e8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:9cd2f57c1e45c6c39674021bcc3dbb163a164af2a0e6f94233231f674ab51a9e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:1397f63c5b08fa14ad2a97c632586ff421457ce3572d90f3204a26a0bd5f9bbb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:84e6eb3e72cb35674923e4f33ec03ecaa73a3d6e9de2df18e1b789d8bf9d0087
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:d11833e23a2cce568b63c9b46d86e8542b7cbac1daa79b69d04814f9179d4c08
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:9b132494c4c14f19fb504e6f4548b33f35180cd36b69a504379612670766167a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:b41ba6a7e0b6ff3c0adedccfd4bd1f7a8812f84801f6b7473ee85c239fc0aa16
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:a679fa8d90cf1a9bc5066c9d781fdfaeb22a0e0d1e551d207767e94e68299027
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:3b92ebfd9af9f823c650787441fdd44525756c9756d906471ee9e7299852431b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:adec1ac4d55e20639f2b03b05a2bf1bc140361af9b8d1e6a228499c8535003d8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:5e5c030b51e16841f504ed36115c764519a920a7e940fc438fc90e452466b070
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:bb0d37f1991f7a493840a2945f55cb5bb61ce4387050a1f0d6205582425af8bf