Sign inSign up
DataHub Actions

dhi.io/datahub-actions

DataHub Actions 1.7.x (locked, dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked-dev, 1-debian13-locked-dev, 1-locked-dev, 1.7-debian-locked-dev, 1.7-debian13-locked-dev, 1.7-locked-dev, 1.7.0-debian-locked-dev, 1.7.0-debian13-locked-dev, 1.7.0-locked-dev, 1.7.0.1-debian-locked-dev, 1.7.0.1-debian13-locked-dev, 1.7.0.1-locked-dev

Index digest:

sha256:896c966b430ed4e492dfe27b9b310f91981dcf8e58a22aed5e65b1b0133c3222

Manifest digest:

sha256:8b50d8a17f8c124426ec3354f2a02218e733eb2eafbd8f2615ab95a5a06960c0

Size

88.31 MB

Last pushed

2 days ago

Vulnerabilities

0
3
8
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-actions:1-debian-locked-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-actions:1-debian-locked-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-actions@sha256:43c4344a6ca3dd3a11d229b8f1c2a379c93febb2c0ab0a9810fafec7ebdef6b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-actions@sha256:072e767d64b6b33dd4a51ef17772745bf425570556927220b05ccc000cb6dbd0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-actions@sha256:9aee78d3a934e8061551f766ec8b15ad6d97f8fe5e4dff869029d824d962dfc1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-actions@sha256:bcaa4861b68033ea714786f79e27f0b9c45ef1014aacfd3e7bbdea4280ec1935
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-actions@sha256:db0aafd2668f46687fac678043135c03bfe761327feab4153623556ce599df8f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-actions@sha256:49dc510616cba0f5c6bd16262d42bccff2c49d5c6e4e88ff1a9ce8c9dd370ee5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-actions@sha256:3fc63e14f91db842bc22491a267a243c11f46f43db5113cc25e9485da30dd963
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-actions@sha256:13b0269a20fa37de97ae4c93e592948d0813fbd2a225fe26b6dd10ba78b5a91f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-actions@sha256:a798e1ab62bbc9243239ed5871d6798e9a2dc9686f425c16fdeb76c305cf7310
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-actions@sha256:32482339440ae3e2562258a84fcf0b94a41e19530e5cc9c4187110fbb80df536
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-actions@sha256:9e2f066ac056292287ec8cb86ca9a0464ce382d90557b948e2e2ffc3e0ba8665
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-actions@sha256:2dd33c84ecc10d19a11757e203de2727117058ce8847175c1d3c03dc4914e2cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-actions@sha256:cc35753bcac6248e3d9d7d4e099be127eee4108e7c58d143b1dac5a5631e39cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-actions@sha256:3efda6baff8bd4b48a4dbffb7d5830c421a70185dd67bcc6a5b74673c95782d5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-actions@sha256:4572a91d33730387093df5900f1b53a3941a5ee3607fb017e417860d2f47f068