Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:688c897bc70c04386e0856e6a8a7fba1a22251cfe3e9b2e6c12f3b3e00141e65

Manifest digest:

sha256:5d6fca130316732712aca6faf4b8dd1a2c55ae19a364e10bf0d1c12286825cff

Size

707.52 MB

Last pushed

6 hours ago

Vulnerabilities

4
12
0
1
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:92c907fffc99c32db1630d88867b71b7419a787deef1c4c9d40363fec7c0c3d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:525f2d2aed05b53212645a98f4ae452c73c8ab8ea912a436c2634eb89bd58045
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:c5dc2792d82776beea2ca2217e701bf401c1a034987f1ac06b3c0b0afac179fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:99a26fb8dcc359a43c6853e9a17b71f6e0ba3d35e88b36fa72b7d913e753a349
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:c1180396436d9d89d74ff34ac70bfe2409192e23c1ea1011f4ba2639839b67d0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:156a2efe8578c09747c768883715711a49798c4aaf2448b720b2b5c65a9307ce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:6f00c38f026011f38d98227127cee754a2c11ade8d64b945c16cc74061a0b8eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:458ea650b88d7eb8b30f9c7b124325070dc176a9d8e997ce44f48ed7ef4eff04
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:d6b18a8a4f968d7083c1fd8bea98637bca9fae0c81ca5f99d0782947bfbd1926
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:22abccf875ea5a633b0dbf36c8524c3b2f023b072ec754e8ab77af929f3ec055
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:da43434c2012f95f835cd77b935156664ce69c2e69d4991e9239e08f9fd0a5d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:cfd6e1b7457e65c0ce16196a6df79ba5de330ed189eb1ac67b1d8c1d5514eb56
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:098e6a4d81590de64b92a1236ac3b22a0e8d35541452f932234fe799f3674727
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:2ad61c35f5654d1a78f62d34791cd7715b24d99783d7906e4b4a9f973f751495
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:0e3c205592f8ea46606c2d12db6ae7eca1b0926e028634642012e63f1a70a186