Sign inSign up
Dapr Injector

dhi.io/dapr-injector

dapr injector 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.18, 1.18-debian, 1.18-debian13, 1.18.7, 1.18.7-debian, 1.18.7-debian13

Index digest:

sha256:45d2e76249b4f12e58ecf4d255bec25932ffa6628cdf49f4f302307de2776af2

Manifest digest:

sha256:5270f4b2aa23c4b39c05311e4b421c846d470b9111459a828f2502fbc7bb5f7b

Size

14.21 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-injector:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-injector:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-injector@sha256:28177ee8ee49a10a2ca7a1254a0412dbbf6afc5d37a0cdca20168329febdb78b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-injector@sha256:e7349da0f3d876f8be99e09624e454fe6426cce3bb636da38026c789cfa44b9b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-injector@sha256:4aee61d00cd2f28ccadf454a5e1306eee1d58f17f5e77eb4b619c50cb4b078e9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-injector@sha256:c497113cc53a4b744aad5ac4291e09f63a1e4979e0d5cec248d87389912cebcb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-injector@sha256:4502b0259ec389f99f62e6aa233f52ea76b30945998a97db90b1617fdf00edb4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-injector@sha256:1a87b0929c400a2882cce90ab154aaa8390eced78f5520fc2dadbd690263c976
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-injector@sha256:305433eee052acdce6e1b7145be563f4f1f4caf1014187c3076dc2fe9880da21
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-injector@sha256:1dee1843e9f6b5554e9dacbd9fcc5669e3d36e459f476466d49895ff9715a196
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-injector@sha256:0e19d460f6c42008d44cf3d03c6765224fafd0d1811b09d026c078a9761c8106
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-injector@sha256:787b326b0502369c28c2cacbc9d7ccfb1668574d5c057112573e2f80244bd224
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-injector@sha256:17af8289611fee736ca0797b5964c3d69bd97de8653e9d131adc1b766574969e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-injector@sha256:1b86e68115e4eaa304125818a184b00d43c34e18f36c686e5e4f2dabe22f0eb0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-injector@sha256:f08a2190fa948593ce841d1afb87b8551b3555c58b9422e010391c49bac1b268
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-injector@sha256:5ea86abeac389c7fc9822bfc7a7b7250f39810cd5955065e14206fd64cf429bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-injector@sha256:8b9c8e4b64776325c74b67a695d3b83a151376ecfa0be51812499b281335854a