Sign inSign up
DataHub Actions

dhi.io/datahub-actions

DataHub Actions 1.7.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:130ff2aae6ddbc373499e6516d0cc424863b8644b1e1b6d3abc7d8a47dcd07dd

Manifest digest:

sha256:ed4bdfa2bb606189f7710ca93a5f1773189be9390101aa0e5a261fb618c100d3

Size

120.18 MB

Last pushed

12 hours ago

Vulnerabilities

0
3
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-actions:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-actions:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-actions@sha256:71f0f853dcc05d75ba2bc75969432d7f5f50de05c50220975441c1a8c3cc0fd7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-actions@sha256:d3b04626487ac8c6a2aebfa373791c6114436f20d23b6f8df08616ce4b505cf9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-actions@sha256:4b9992211940a35105bc98ca732203dfecc6b4d346c6cdfafeb56e3b9488be8d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-actions@sha256:bb306d0885063b11272bd4139632cd4bd1388357f1fcc7fc23e96b331bda1484
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-actions@sha256:5d6588635e160826683669c3fb1e2f255f3b9511ff1a04010343bcc522c04da6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-actions@sha256:7590753bfb4cd4e89cce87326368b96d396fd1c4d3c3b7a22025bfb92d748c70
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-actions@sha256:534ac299d2c371842fa077b211c8fc781c9aa06f9a698a5c2771b58d4eba2213
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-actions@sha256:fc41f573c372c7fd185f8a03da59072d5f88db6af1f74b53c4815a585d888112
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-actions@sha256:7fe3b40f25d22670ac94edd05147882ded1ac0b1b3c340b01cb6b7053b8d5c44
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-actions@sha256:31b0959c90331dcb0360ac18444922c1e53f08e59988c008a72d8c2cb2f79366
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-actions@sha256:2cb5bdf5d9fd28ae30b2856457f8ea6385f57b0e0801af14d1a6d7591abd6477
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-actions@sha256:174c0b23166a816ea7b4bb5fdfe67fdbc8f481feedf9711538ed8de07d124476
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-actions@sha256:a0a5d3d50001ce90d9d865f19fdeec8476424e7c8b7d528653fa1171d8c54098
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-actions@sha256:ddbc680c49df70d6c11a6e4a7702f97b036150f4349b49e4447388441923ca3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-actions@sha256:2d00f3590711276efb3953af42fe2fd7bd530954c3f68bab6650e2b69b995402