Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.0-debian-fips, 1.7.0-debian13-fips, 1.7.0-fips, 1.7.0.1-debian-fips, 1.7.0.1-debian13-fips, 1.7.0.1-fips

Index digest:

sha256:131cd8ff63f24e65bd7cf37dce87bc18ed8cef0872d8efc0ae067f170fbdc439

Manifest digest:

sha256:7cd5c81b4febfb0a942bfbaaff9a5212928cf66c0448e14ff98d201e6a7ec737

Size

611.31 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:312fa44ecd9a4cee7e6238d1b748bb70b5f3ed1076a1ae836046cc4e4ca4fefc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:8fda0743d69440fb07d326f898f23d96a92311b62241f00a74fc1b4c92ab173c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-gms@sha256:ec41d6dafe82edda4f0b1bb9689aa0a2446912ec5022d12269d7d1b1ae6ba7d3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:ff67af0675a251f70122ca3c242316853695406998ea1ae524cc11a20f7b5b34
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-gms@sha256:4cea3d632b96454ef349c34cb0d147094c2901382533c6e7bce1512ac01010cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:6ebf9ba84944f8aa458c98af22850d722b31d87dab62045a28468d67f6db65ed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:23207420e84ee16cb2034b330f43e76e997d0d2f8d019e74047960543bac3598
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:da5aabf85637607c4690d668086bf1895f6323e077ed74e3e64ac0c4e48dd4c2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:2d8cd5a882fe1904542c6979871b512496bfef01731040b5d70fe6e2e2b0a788
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:e846bede798ed979d9546a38207e468e83670e22e54ceb9b2d58160a820bbe86
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:8f68831fe5d99465eece72c59f0f0998ab2c027726018b87cdef8fa20d030a05
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:9150c80a1cfd00f3037029cef880bb07d69b8058c68857bea6547a3de22a657c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:fa00d7491cec2b9a04b10c908d51006b46e8e7612b27d2958d601d742f114ecd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:f26b26de362903e8e55f21e877fca15bf33e27fb34c16dc44ffed1e4c09bd299
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:15adc74b71537373ff9c0ad1ea7eeaab140a140225c785094e8a57befb2151f7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:db375a429c7cb71716efffbcd86db6673fa8550de208169cd1a1cc5f826e2717
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:163c8b35317176f571487dc7a6ab5b8aa7dbfe639816dafcca91461dca7accfc