Sign inSign up
DataHub Upgrade

dhi.io/datahub-upgrade

DataHub Upgrade 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:41fad041a87f99803dbaf599a00a89a1d629d56b8608cdb84b3961c14912ec6c

Manifest digest:

sha256:66dd38be7cff59395549aac15936117fda885f86d6ee1a3ad7e39c5ba7ad4276

Size

794.72 MB

Last pushed

24 hours ago

Vulnerabilities

0
1
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-upgrade:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-upgrade:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-upgrade@sha256:51df01f96075b424624f0fc7b2d7ce1412359a3702d738c1155d5c23e264f4ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-upgrade@sha256:a1b679030d7fc9d93cf3b13407c9d274196d4f9fab17b6ae9402152ac5d7dec5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-upgrade@sha256:c2087fc48e0dcd96f991585c71f3165e9fac0240cddd92d92ca23fa47ac4421f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-upgrade@sha256:174a2bc37c2eb09d4078eafb2071736731a78a5972ec5171d82801ef0408840e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-upgrade@sha256:3b9ea0e4aa1f477cf3deb276c95592983145b60c17d0906f75fc715ba1e809c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-upgrade@sha256:16d382bf1981efc003e232b6736317235795c4c694cbc6840a3904655f4edbd6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-upgrade@sha256:e3fed38854514b355ef8b599a3bb38910b16a12970e2a5e200d90f3a4f669ac9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-upgrade@sha256:04250e4fac06d4675024926187dc5a7f42c422746c71c99368c9edb519c8c743
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-upgrade@sha256:be94ea806a298834608bab1aae380d617f6139550285b92ec760c4c53a4cd197
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-upgrade@sha256:570b0a0a0689d5ed67df05a4a3536d07f0569b367112def56b04eaf6efd85317
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-upgrade@sha256:eb4fc78c9f096c296beae6cf111980710efad2cd692c868f21f05ae5555f8c07
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-upgrade@sha256:7bda2a111a450354b1e727e15ebf42d7573004accf42f1bd3be31279d250c020
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-upgrade@sha256:6ca091437178ca4fd03cee0c5c6ff187d104f11d017135ebbc121bc27d260c2e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-upgrade@sha256:fe5040ad81262db49ec4897b2ca3c42000db4c0ed8974efa24176b0dcd2c6ca0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-upgrade@sha256:8c8f371eb2b4889253675095f71b3574c1e38c1c73ddef452774ab05ace7a2a3