Sign inSign up
Dapr Sentry

dhi.io/dapr-sentry

Dapr Sentry 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.18, 1.18-debian, 1.18-debian13, 1.18.5, 1.18.5-debian, 1.18.5-debian13

Index digest:

sha256:56190a6092bebd70c679b4261c8d04d2f58ad35fba6765e4e6bf565a5b367c21

Manifest digest:

sha256:966b2efa63dbf740513751d941807722166ffcbc6e933f8dd5b383fc96db824b

Size

14.50 MB

Last pushed

10 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-sentry:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-sentry:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-sentry@sha256:fbb15394d5e48bc34f7926c509b7986bc63e8ef59c22b36099c840d369f69ac2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-sentry@sha256:fc6a716e432588f9fe65290d20b836ed9d322db6974729c3aeb62c56d4b9c810
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-sentry@sha256:afbbd6ce2174e64c90703393cea4bddd68641d9fb2367b0ee24903550c99159f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-sentry@sha256:f5c24a56de6015915b5aa28ed3d6238275d75b4348dd8e23213cabfe5fdae7a2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-sentry@sha256:d2dade21e22762506664a323c98c17fa11dddbaa26df94dba1258e8b0de93acb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-sentry@sha256:0612f7db84bb88ff5d4060a7c441b6b982d1a0e27d7c6b7a2030a821d9fec29f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-sentry@sha256:79b7b383db8e2c34d46cee69d5f1ff52bd34aa24641355d554c6e111cf865ae0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-sentry@sha256:05897dce4cb1e933fdde33637fbe5f6a3a701bbce2f374f76e7e04a26fab44f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-sentry@sha256:871bd0f05bb126fc7e14caddbd55cbd34abba47ef4266f20c8ca05a6c5dd98e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-sentry@sha256:c274ae3ee7b4b82c7484969459296b840a6ecbf67d5cf91d933d8972e12a55e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-sentry@sha256:2b4bc35664632a1c7e3ce952130c15685e0c5d2380fbe1658d3eeb86014581fa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-sentry@sha256:1514de709eea8d4bfe4c2b47150841139a8cec76a24c41bf246ed0105578d8ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-sentry@sha256:902b15f9ea22e1b6eb7f0ebc37b125b5f0b5c19bffe4e51249c2906dd6d3ba98
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-sentry@sha256:c48ed98651ffc42d0f3b9625d9b1ad35d3415f836d62c5f0730617bfcf2b2edb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-sentry@sha256:f3a218bac31ca2f05a108a3f5e9cbc6aeb1d35ae7f36ce350894c86dc69f5b07