dhi.io/datahub-ingestion
1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.10-debian-locked, 1.7.0.10-debian13-locked, 1.7.0.10-locked
sha256:aca9de1600b149f2ddf3077bd758bb1f3c042918ffcf6644f7d00a04be75b9f7
Manifest digest:sha256:1fc34e03db2d9eb823b29df9fad70b569839eb0807adf3cdda609e028718ca8d
Size
129.33 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-ingestion:1-debian-locked2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-ingestion:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-ingestion@sha256:da7eeee6197ce5f3ffd39f74be7ebd6a9acb6be99fd8baf52d9299a641b3fad7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-ingestion@sha256:ad5d7586a900cd1bf944f53f318d34b47bc1f861d95697a1ef554fb0a0f2e4ce |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-ingestion@sha256:c16bd53c80d004fd5a6beef450978607718489d9983d7023dbf0f8e7ff142673 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-ingestion@sha256:3fb029b1712eb14444d8c3a956d5771ee851a3e0fce3ba08fcfacb2d0d798245 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-ingestion@sha256:137e8592d291efa8492b76483d468b6ee1a19a847e68b744094d7cf4fd538427 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-ingestion@sha256:ccbfaa100f16fe8da8e3383c24527a95b7a1b83f335e3681b733eed7cc118c1e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-ingestion@sha256:aeaebd2b47d959ac8187e17ac106096513b3c21fa90af5e106d05909cb0521c8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-ingestion@sha256:3e7fe57ee7c8298f73481340de58a25f83eb1352a1040dc973564c8e94a6bc6e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-ingestion@sha256:9500665f5e15326fd6552c14f795c7b14d0c2f3ec3f67febab9ac6404293e192 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-ingestion@sha256:86f90c3316647ea603313e6b23ca449de33f3c17c15ce3b3b973af95bf84e2cb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-ingestion@sha256:ffc293f456997087676cbfcec52a914ed0ed5cd6faef46caba2d15c7c0545fea |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-ingestion@sha256:7ac2bb05ecf7c34e48bc3617d72a9d3d7d85b3988a1ab1969ebeee431a7c181a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-ingestion@sha256:7508137dcc0192406177dc5a05ea38f110b9e6fb60db4fd4930ce4e2c665810d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-ingestion@sha256:7fd9ef69517d02e493c4aa3fa0f850b203c279a144ae1528ebd44e1884d898d6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-ingestion@sha256:120bf16254411938e4fe4164b08711c87d2eccb69d8d37510ccac2c48ffd9954 |