Sign inSign up
Dapr Sentry

dhi.io/dapr-sentry

Dapr Sentry 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:563ed1ae8a9286e8064b467ad876427b4d68cacf9ad98d4428e8878acadf82a1

Manifest digest:

sha256:5abb623f7f75027fdb0b5983670c1d2bad1985e23df30725a3fec6e9e0743d30

Size

51.05 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-sentry:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-sentry:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-sentry@sha256:5e44c5de2f11c47465c2dee0760c95cf55a3b7c70a5f4d437f10b2fabf6f4d0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-sentry@sha256:b58ff4a3eb2ffe80b73833336ed1989b7f13896443a1e2c63547828e910ab96b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-sentry@sha256:fb990914ccc7920e411199e9ad7493a3ca1704a0d5dc0e7927b639e3ec61821b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-sentry@sha256:4f81acc03bb3816119066a11dc5f4bbcac7ea2fdd43b405b1fbce0ab1553a0f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-sentry@sha256:40a0df475cba5135225e03fa2fc111fd50e96302d2217acf5f2e8c5cace5ed92
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-sentry@sha256:0eb5eb84292ddac044539c3ae5b444690dcc614ea63704aa286eeee4054fcbbe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-sentry@sha256:a9804e372367c7483b8987b499ccdd445c72e7d92071b991ce553878d8f2beb5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-sentry@sha256:61dfd215fa529370bd65c2404bad5ecd99e7f283850058e7ae1f9080fd1a22ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-sentry@sha256:59176f845dc7c9227b2b3143b085694f1ea62f27f5ec147d32376673647ac9a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-sentry@sha256:a3ec2d60bb29cff739099c13a1e8a3781a7c74192bff9c0eba0ce109431d2d76
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-sentry@sha256:0ae713f7892b29e11de58cd4c81b43f09fcae7a9ad21f9caf199eb413fdcd13d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-sentry@sha256:e878c1f56343afd489010a55a0aea552b212843a3b7921569b626833340e4035
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-sentry@sha256:f5f214935a2264b0cb8331f898d876792322f17a11df32cbc9eaae132ab8207f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-sentry@sha256:970f3e536788bc52f01bfb2e10b61a41da59c62ccafaca4e2586a0ac7aa23972
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-sentry@sha256:e4fcf2c03f41c4463918c9943bd9b75a86f777b58c897dd72bbc213fe6010653