Sign inSign up
Dapr Sentry

dhi.io/dapr-sentry

Dapr Sentry 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.5-debian-fips-dev, 1.18.5-debian13-fips-dev, 1.18.5-fips-dev

Index digest:

sha256:8af010d1a9e21bc7a5f1055ce36aed5adbd0c8d64b102ab8a750b1683859f45a

Manifest digest:

sha256:061421114a02c100937bc3809b37484c178f6a2fdb454c35931d026620517c1f

Size

51.84 MB

Last pushed

21 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-sentry:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-sentry:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-sentry@sha256:c7dede31f2890b25fb3f32e7282c4a49b0e9ebb8ff9b9b680c7559b4d987a80a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-sentry@sha256:d42c323c8940c484f0834d07e785c06c497f8f3ceb5672be939e1f407e692ce1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-sentry@sha256:06dab50f6a9c55afd27e3a964a67aece8beca36a6768d76b7d0f12fdff04a516
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-sentry@sha256:5909723dfc3838eec28ccc11697950cb575fe23bf47d9c4ccfde9eab356e807f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-sentry@sha256:758d304e813d96d5b681406297cd59783ac398e6377475253851537a5ab9a415
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-sentry@sha256:b17b6a39421d4d81dd00f250dd7319d7636d1adb03b2db7de0822058863a6aec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-sentry@sha256:c9ba0d7dccce266b22793c5977f78828f2c46395b45948a744b6c08d8e3d46b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-sentry@sha256:ff1787690fc5f8460715820831a8799b9bbbbb5efaa11bfe0315b3b87d5e9f46
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-sentry@sha256:90ea5437485f2942952a7ff484a7abd73e82632c278be746f9270b5073811a23
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-sentry@sha256:07bf3fe4136941314c215bdb3d2c225541d21ef26a0f1ff9d7a9d86369d564aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-sentry@sha256:d4919120b2b29d2bd808d9b654ee7f98aa9d1d3b1edc001b4744eabc8644e853
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-sentry@sha256:77b9a3b74efe16329e80b404f3f4022500f219e6f1ec499a9ce08cc0e6298d50
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-sentry@sha256:104fc587d3f445ddf5ccbfc9f81fb11ed74690f4b5967ad8028cc74fcec6d63b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-sentry@sha256:8c2139f10df7d3c0c357b1f420f1863a53ccccf3fb31ce4e9d11fef3e2b68468
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-sentry@sha256:e99e62d6f2c5e2c5d1d198d29240c9533670bd23d65eb0e24d15b459ec36f08e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-sentry@sha256:e6ae9c57716fc645eee7624cc29024c3ac12b047755ae19968c26affe45a0177
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-sentry@sha256:8a618822aebc068d4185fa9e83226afffe62bbfa2037ed4aa903d9f26d0093f6