Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:51040d1060c4c861a09a7934b6029a251d4c6d0504ec39efff05e00beaf5e89c

Manifest digest:

sha256:73654e9bf198f3f18fbf5f6221d8ed8bb704183d867c04c6d3743ac474e47dad

Size

130.25 MB

Last pushed

5 days ago

Vulnerabilities

0
3
3
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:1a00c372c7ba96f2d67306132e42ec17cb10bcb4d60e58017740d695132dd439
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:398605ecd4235170fa62ae082eadfa82e5541b445cae54be1bd25703fcd02bdc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-daprd@sha256:f041e732f8598e849e84a2cc63764c230a8099903e717e0379bc66e07d306d95
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:ff0e80a6a06eedb4940519523992d92e6f05e98ce5101c63291cb364d83903c6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-daprd@sha256:493b2132c7f46cd5ee43e02e3cf3bed3ecee25e7b4f05ad37152711bc813702c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:4eea0a724ed11426f1e51c57e9c6749bf52db9c78ed425afb828212a25876d37
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:09c59e77cb27c7f69ca585a1a48bf11cb60250839ea7c5de23805aee7836e7bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:98d69e4885f83edb9d283c96f4d833ddd740dfcb16b2ed7989e02aece53529eb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:2259799ac208d36cc80196b9a54643832166e094849b3693033e0f3b81119bf1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:558d36b471348de414ec649159f9927a6b64fbae8781a66fa8e36267a8376c0e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:51aec9f2e2568e7fde3921b70b710aad4ea5dcec97b7169b59f014bdd62e2f0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:187676776d5207e849aed780f7e54bef515705c73e36a77d416ba4cba9b137f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:2d73fce942ccb83043560d9da01ef7b041394e591814738e620928d04834bf81
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:f4ce8c1b888d1d8bb52401b89264620c2da1786324bd89a0856fc5db0641c0c2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:11ca01c277b4501a0c10e8418bb67a74b90acb573d5528b4ca3b4a8e24bc1a2a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:a533bb0298c394c972b04ebfbbc5247d4637f7cf5a52724457075b1b1a5c406e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:47e4d0352e9dbdc4b0a3d696499b725ce1f41b0e6edfafa1f875e49a2b799413