dhi.io/dapr-operator
1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.4-debian-fips, 1.18.4-debian13-fips, 1.18.4-fips
sha256:f1235c1dad5e49e59283821ccdd6dadcf88d93c9f59df953ecbcac319b659fc4
Manifest digest:sha256:4f67bd04df7b21b5fd3ea93675f65fe8cbcaecbf0adb48cfd7fa2e6aa6144c40
Size
22.69 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-operator:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-operator@sha256:00f61f9d32ce49e720a35097913f588bad34f1c01aa92d5d4656fb2d5c7a1763 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-operator@sha256:30e2ea23f231762afb6042298bf698af8956d5831f33992b640786e6dc1def21 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dapr-operator@sha256:318db16799999870a0e729525f92b2fe5ffbba7da4b9b6683ab1c6e89d6418d4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-operator@sha256:112862e6ca6e86a197ccb2d9d3a5065badf85c2b0ff3ba9201e5af7b4b28af24 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dapr-operator@sha256:ef44d41a8ed1fa616850c6abcbb9d9687c78cee73bf43813931b7109f3f7f5d0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-operator@sha256:8a3f08a9220185e7e518c7557729a5a424a6419863607181855417d68422985a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-operator@sha256:b9b52da51d1bca05bd0948c244c0c942ad1c77e273eeb907bc71492ed9118f4a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-operator@sha256:20a261632b2fc1cbb8e680b9cfed1218e738328377142dfe90f1fcd5c23ffe44 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-operator@sha256:498774ae84cbe4efbfba073edbc18b32f211949586f49acb996c0858a449f875 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-operator@sha256:bb36bded0a8f913c3ce0b448b239d418bb94c3018fe1aef9abf479a245e77bc3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-operator@sha256:ffbcbc357f57828b3ef0c0db1bf5d9f4966d6b6c1f82bf72b97b433ef07b8fe7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-operator@sha256:81525e541b0316125256efd256b6fe09d3706ee84fc1378e4501a378b5515479 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-operator@sha256:95b24a676aeac1b4928a4d4327ecff392edb2165fa7f25c870d9597396cd1957 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-operator@sha256:65fa92f718bfb70cfb90a9dd4e203559cc13d1faffe61b5e36e38900999549fd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-operator@sha256:8437722e5e94dcc8960efc07966121c5ecdb36227a108cb3613beaecb68cb9f7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-operator@sha256:17e4e274845c3128b38f466964755c551bf94062dd9b397ba2d254d50ade6e58 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-operator@sha256:327aaaf9619106e71755ee6d71e215f3e8f6e61c3edf45e248d056959898f044 |