dhi.io/datahub-ingestion
1-debian-locked-dev, 1-debian13-locked-dev, 1-locked-dev, 1.7-debian-locked-dev, 1.7-debian13-locked-dev, 1.7-locked-dev, 1.7.0-debian-locked-dev, 1.7.0-debian13-locked-dev, 1.7.0-locked-dev, 1.7.0.10-debian-locked-dev, 1.7.0.10-debian13-locked-dev, 1.7.0.10-locked-dev
sha256:63d5eec12ab01b0f7d84aafc5ac1e85d43d60c3cc48b971724ff778a6ae291ea
Manifest digest:sha256:98e1c5b5dbac321f1dc2fca0551c0e0a5be7ecb1980f8bc1276ba603fb405f2a
Size
141.27 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-ingestion:1-debian-locked-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-ingestion:1-debian-locked-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-ingestion@sha256:03a4c9dbce5a9f221cab70218f31c9ce906fa3f92c910ee63642b985dc48ae36 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-ingestion@sha256:b4b0fc0397c5b66d65f7b4c4db059854d15edf3e4b63d2d92851254c56cad463 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-ingestion@sha256:72af9565535d3a0da1de068276d303359ee54dbfbd158030d0dc94b4add01ba3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-ingestion@sha256:3dcef8a83273be9e812264d53e00e9c0c60e952b4556bddc4b79a209a2e6db8e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-ingestion@sha256:e19fffe919a070be862d25849408d3de22e8e87e3427baf0f5d17ad5898ecf7e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-ingestion@sha256:e6251a2c61c698464ede790f53538f92528492f54ebafb544c5b634a7ba63cf1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-ingestion@sha256:ab3eaafd3a9e6d3062f1284f809bb39fbb86d45b334e27f98a371e8870e72dbe |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-ingestion@sha256:b234e342b2b2776bbcb3026aa15236aedabc6aee049eff1f8f0bbcd51a4197ca |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-ingestion@sha256:ede4e454cc6c40a68c8d8e9f1c1edd2e3874b15a2cf792a6f0bfdb8e700e6cf9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-ingestion@sha256:a0b6f5b81b0034ff9ccf7b9e0a030ba257820d5d41ae0e24237fce8c57a020fa |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-ingestion@sha256:9ee6494f490c82cec19395ab27605c5b8958847946c75882238042441a1b4dfb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-ingestion@sha256:8df9302ae4d55ae51783ca2c2a95f692d1d5ccd6177f41ff2340f6ef9a98d6f4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-ingestion@sha256:258e34bd860677bd83e7a788807144a52e03f71d514f2743ab5f69dd815521de |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-ingestion@sha256:656d91a935498bab040eec97fd0266761fbbffb2b5f855e964ae4ab29d123351 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-ingestion@sha256:f67f30ae355200ae849ac3ea2e0734682607389cd88dabafa61eceff2fbb319c |