Sign inSign up
DataHub Upgrade

dhi.io/datahub-upgrade

DataHub Upgrade 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.0-debian-fips, 1.7.0-debian13-fips, 1.7.0-fips, 1.7.0.1-debian-fips, 1.7.0.1-debian13-fips, 1.7.0.1-fips

Index digest:

sha256:8e2450de5c90a8f77e0f7b2514dac9f1ca687053c9bbc5e48acab8b4b11e7533

Manifest digest:

sha256:eb1243a5270d484967c52aae460fd85733d47d23c2144b094f1c65ebb1e55033

Size

670.59 MB

Last pushed

1 day ago

Vulnerabilities

1
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-upgrade:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-upgrade:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-upgrade@sha256:20f5a9ef73adc5ad1d3bb9df77200a355a69bd8ea854ac4daf2a38e43ba3d56b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-upgrade@sha256:231be290777cc7738d84e6c8506e45a69006df95792c4b39cee9ffe1abdd2440
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-upgrade@sha256:ba4747ed82e06a758673ca238ec312cf0f5c84c0311f1c227a1a99929f67b4c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-upgrade@sha256:667f07862cad9a6586f9c9d7014274c628d5c63c035a99777e4a2172dcb2ce2b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-upgrade@sha256:3dfec3ea1d626f381afb654fcd1734f24af2ac731afbedc9f83aa42531bfbd38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-upgrade@sha256:66ba4088dbd84b5315614618f5983d603a9511deb04776973c71431b66c9bb66
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-upgrade@sha256:5335602ae49f1044755d6524eff1d6b401105f9363f734fe8b3b9131dfe2584f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-upgrade@sha256:28fb0a041a00cddfa22e141238300f7adbe526e247eef5caf800aaab31b44239
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-upgrade@sha256:9e53902ba04b0e467e849e9b65d0dc425eb910007cacdddd5f4cc61fe86d481c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-upgrade@sha256:36f12cceee3aae1a8ef6cb2970ab87d204b23eae438dc234b0cfe77ed791ae41
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-upgrade@sha256:eb609d0414f957c159ebdab0ffa29b8273a31237c7f38f60bda78c858bd4e7f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-upgrade@sha256:25e3719e62651378177a5f41907a33551b54fb3b67ffa0ce3c771e7bc63e9a56
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-upgrade@sha256:86ad203d666c3e137177fcfdfc14a3a6cefbf84a5a097e427c0ab2d0a99b5883
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-upgrade@sha256:1802f6e13f9c52ce191a467d72faf0bf172f96a8ed731c6326bf6afa52b94ee2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-upgrade@sha256:d0c8a1b65e6243ca1ba8c26d989bd50479d12390589b237fa33c9a9b9f989d0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-upgrade@sha256:f7754b91e4feceb67926a316cf717b5b8f60706ab31d98bc4e6725aedf53a4aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-upgrade@sha256:a3f0ed329cc2962202045deb40f34f637e1cd19eaa84c5d11e658d80801aa5bb