Sign inSign up
Dapr Placement Service

dhi.io/dapr-placement

Dapr Placement 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:067c082b3c1b422f031d74cbb5e320a2c9f7047e05fa076a0ed51fb9e962e349

Manifest digest:

sha256:b0703c2342b4b81ecf51bbb3c683aede7ff71ee3bbaac0a8e0cffd66e3e6bea9

Size

48.65 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-placement:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-placement:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-placement@sha256:9e3093132a62ab770ffae224d94cf7227a1ba5744af92e0bdf2793dbe9d5b79d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-placement@sha256:95f4c82caf04fb995eb66568a28d5821db546f22aa5b19f6559905288a14a4c6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-placement@sha256:8671d76b6463e3c137b52cb636ccfedd43cb4cf22dbf6e6d0050ecd8ee19d293
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-placement@sha256:cdd960fdd3f7b5a039e28dc866520476815e44c20504c50672edf48a5fef10b1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-placement@sha256:4a565dced8c17f90c45fa716afc66aab9787e2c15f7add15f7cafaf0a2f47512
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-placement@sha256:a8dbae777646d5879e52757a9fa32cccfe019061c2c20be620c9c8aa3035fe2d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-placement@sha256:7831facfbb84eccb33c4699a038aa80bc4f5a25714dc9729d8e1e2924a0a43a8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-placement@sha256:9eaeb9f47690aae4dd6059124e1bda05d9e0623d1f8a08e64dd6461fbb98fdb6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-placement@sha256:c507d3f099a8a71637ada6d8a1fca3ae2e93294c54b738fff900919ea1b249ea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-placement@sha256:f854eb43827319baaa8600b9097416db2013e7024ea540a965479fe2f03d7823
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-placement@sha256:10bc07c6045172d9793ab073e24f7be4a9a103c77843747270cc3819b809ead6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-placement@sha256:6876cb67652c5d702a89e92af5f0b7e1007c10bc07b52be447e7305341d63f6e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-placement@sha256:369505f261b08f4759f7b25e3dba615107ab1ad43dba2eebc3bfbc643cff6bea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-placement@sha256:719a686069393b3bcfc6d972859af14445f2df7d27e36aef7c322b5e209aa1ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-placement@sha256:6a40851e982367b3d94613c1c5c3cf16e751be302eb1378f8a02ef46168a0c62
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-placement@sha256:dc1772f2d63c93f72d0a8e4c7c5bb9649274f620060c82fdcfe1db98ce63e165
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-placement@sha256:538c69560394efa211dbf82553098d7dd64b7cbe2170ff9678713a87243a7299