Sign inSign up
DataHub Actions

dhi.io/datahub-actions

DataHub Actions 1.7.x (locked)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.1-debian-locked, 1.7.0.1-debian13-locked, 1.7.0.1-locked

Index digest:

sha256:227705d7634ff1a99d048fbcd65d6994311343c03415826ea731138999e414fb

Manifest digest:

sha256:01b7ec90ebf7598372e46426dd089b4c84cc5f7eabdceeb66089caa0e0c07d42

Size

79.71 MB

Last pushed

13 hours ago

Vulnerabilities

0
3
5
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-actions:1-debian-locked

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-actions:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-actions@sha256:c02f30f9f08842cdabea1e3f4355837f82f0fa1c8c6cf68fd2c4db517896a0ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-actions@sha256:840ff387dd246600605c0d7903570ee60f0582f3caf81bd4dbe0927bea032438
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-actions@sha256:3c979fb9e854a4f4960ee8dcce0fa2fcc6edc6a041faf075583e8ecc1fa2724b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-actions@sha256:6f16f86594a44cd093904f8f59f501ac23d882c3dcee6032ce2c672be8675478
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-actions@sha256:131615d7d6c2c42a2ba407625ca14e360034b5afdf820c9519f41a0b32f2007d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-actions@sha256:881e4b871c2704b2a89f1d10ea6ed6bd9592cccf448537f309db9d553ff9d0ea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-actions@sha256:c9dd635ad511c4b60cefdb213bdc56d5514291865c0bd43f4b38b11b2b24a1df
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-actions@sha256:e2150ecff54cfdd7b1e1b705b5a24c428a3dae5d3f48ef5c2e54cd16991fc674
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-actions@sha256:241d78277ab1337d87ccd77ef6bab073e63f72bfe30ac9509907cd440c9bf994
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-actions@sha256:80a6e6d9b7ef450a51c35ce69cd0f46bf38894142b8f8bf19a0a5f26b59d0e2c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-actions@sha256:8eabc7b67a864ef309a191ff5853eb9f39690b67c5e29c3bb1332b1dd7c1d439
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-actions@sha256:108cb130f75b611bc9296a07dbe06f270081e78760e9365aa1833e32830b0a12
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-actions@sha256:d9f2fd27d80fb6b92b41e1d86f93e056fd9acac098cdad16957b3fce94f89454
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-actions@sha256:af6798b7d40377acc29b42e35ff9cfa61dbb3e387613ec57a19d17ae1eed0c3a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-actions@sha256:5bba062499ac7fe216750c50f6c431eacf0e8beb153a5a639110b1609ba97b72