Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:8a07132fa2452a3ef12de5bbd00cad2fc3e2460b2ebcf5c91ccb7bfa3e92ac90

Manifest digest:

sha256:2f6b04079e104201955c2e9d037d9cf8a8c7ea0cd7019f7be54c42cba8e93033

Size

51.09 MB

Last pushed

6 hours ago

Vulnerabilities

0
2
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:5215511a3279aec7fecc379b55f8be7a4af6f0eb5b4fdd26025e3e9068d97f91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:f123c1e1295760c70aad15c91e08865b5646a14edabf589d2ed6e665017175b9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:8d41233b3874ac9a3347c5d90e907c53dda69d32b71dfe17045f0b1d056d60f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:56ef58684efc20ee66f9073e02b32cfbb5ea37f7e257d22d86b3a14dcb7022ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:3377f7cb85c8e2374ec84b6a0f7ca64b5a279a21dbe55390efb6cafb9b92cdb0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:abe349f30e180def9bd1cbaea4dce5af8dac43402ef0a266fa1d73cfb15566fd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:e57fd8a73589ad8b26584f0649461d0ed0e0358d833d19e8701b58dba14f048c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:57baa8a49fb04682fa9e650f17fb97c5849dc45f2e5b5fe7fddb450eea4b90d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:a299760a106670b5580816da013689cb3ba839868360416f3081c2aeaed2a932
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:b264353c0872f07c9d3251d86a0fe892efccd0e04151ab78c5f6aa45a6e9f8ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:12ddc9367ebde209e4259fbc04c55f7e0bae6f22c8c3da09975f3073c0203b2a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:f133ea12058b762454741223f539a3cdc9eb483243cb0a8d8dcdbeeb69224bf7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:ddb9bc8c779f1d56064e26fc15b6fee74e7568bd38c8e55c2f4b805d1d8c9945
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:1aacd7ff434a06ca6f1fb486d11b89b8ed28b833f5071ffd529c8d81312cacc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:aa5f2a89f4eb3fb5f98c533de5229cfd5eeef272b4a2b230a35ad98573879dad