Sign inSign up
DataHub Ingestion

dhi.io/datahub-ingestion

DataHub Ingestion 1.7.x (locked)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.10-debian-locked, 1.7.0.10-debian13-locked, 1.7.0.10-locked

Index digest:

sha256:aca9de1600b149f2ddf3077bd758bb1f3c042918ffcf6644f7d00a04be75b9f7

Manifest digest:

sha256:1fc34e03db2d9eb823b29df9fad70b569839eb0807adf3cdda609e028718ca8d

Size

129.33 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
7
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-ingestion:1-debian-locked

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-ingestion:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-ingestion@sha256:da7eeee6197ce5f3ffd39f74be7ebd6a9acb6be99fd8baf52d9299a641b3fad7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-ingestion@sha256:ad5d7586a900cd1bf944f53f318d34b47bc1f861d95697a1ef554fb0a0f2e4ce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-ingestion@sha256:c16bd53c80d004fd5a6beef450978607718489d9983d7023dbf0f8e7ff142673
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-ingestion@sha256:3fb029b1712eb14444d8c3a956d5771ee851a3e0fce3ba08fcfacb2d0d798245
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-ingestion@sha256:137e8592d291efa8492b76483d468b6ee1a19a847e68b744094d7cf4fd538427
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-ingestion@sha256:ccbfaa100f16fe8da8e3383c24527a95b7a1b83f335e3681b733eed7cc118c1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-ingestion@sha256:aeaebd2b47d959ac8187e17ac106096513b3c21fa90af5e106d05909cb0521c8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-ingestion@sha256:3e7fe57ee7c8298f73481340de58a25f83eb1352a1040dc973564c8e94a6bc6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-ingestion@sha256:9500665f5e15326fd6552c14f795c7b14d0c2f3ec3f67febab9ac6404293e192
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-ingestion@sha256:86f90c3316647ea603313e6b23ca449de33f3c17c15ce3b3b973af95bf84e2cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-ingestion@sha256:ffc293f456997087676cbfcec52a914ed0ed5cd6faef46caba2d15c7c0545fea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-ingestion@sha256:7ac2bb05ecf7c34e48bc3617d72a9d3d7d85b3988a1ab1969ebeee431a7c181a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-ingestion@sha256:7508137dcc0192406177dc5a05ea38f110b9e6fb60db4fd4930ce4e2c665810d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-ingestion@sha256:7fd9ef69517d02e493c4aa3fa0f850b203c279a144ae1528ebd44e1884d898d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-ingestion@sha256:120bf16254411938e4fe4164b08711c87d2eccb69d8d37510ccac2c48ffd9954