Sign inSign up
Falco

dhi.io/falco

Falco 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.45-debian-dev, 0.45-debian13-dev, 0.45-dev, 0.45.0-debian-dev, 0.45.0-debian13-dev, 0.45.0-dev

Index digest:

sha256:2f794e547c2b1dd635fcf32e54c30179991a97fa25b02ebf3ed2a9efc2314ea1

Manifest digest:

sha256:0e7caaf1786c3558f1589bb9c94fcb1e9409d16609bef82b69602951fca48367

Size

37.52 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/falco:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/falco:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/falco@sha256:d0eebcd9cb1da68a5cd8a8cd191da99ac5e821fdb49ded87e07d93028586e761
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/falco@sha256:cee8f4aadb4cba8c9c685f5142be291fac6d5212c00fd1793c21df7f9eb5f0fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/falco@sha256:6a75618f84b6b7a6fbba768459cc45b901c9065d2a648aff14661fc0e2e85062
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/falco@sha256:635e1736159a98889c00952bc854d6632e8a5e510145f8133db7b8a8a6166508
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/falco@sha256:71d06dff83ef0e9e3dc2b30fa2d1dfaaa0ce5fc95f72a99e601a765be859b616
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/falco@sha256:b35ef22ddab93b7098414f3fb8d29deab20bb23e38fd1b5c8ac7309062f5ee85
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/falco@sha256:e5cf324d9bb7ad3be696c5b84dc6cb2719d15334fe605f0e4d93335bb4d08da7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/falco@sha256:cef5959076be7a7e9c3a5f3ba6965744e01ce747b051c97e204a48992d253b9e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/falco@sha256:9a301e95581757ea1aa74c41dbdaf54ff161904c24cd4f036923c59742b5d1c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/falco@sha256:f117b9f2b44074e44eea2cedfe2269ee17f058b1ceae30a4c13efe2d36b4d0c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/falco@sha256:4dea1de5f40a937e7c01c6d2c1ae3c6e8fc428e24c3f28d476d3d90ae4eb6514
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/falco@sha256:df781f594a7c0df6e3935583ba12eadba8319504267dd22e92b6d8df307f7622
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/falco@sha256:01b83a9e37cc33f0e9bf4a8a5357d70536de034354202f5ab28cb432c77b152c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/falco@sha256:684b537a5f7d317d962fb3ad08ceb6eadcae8c07c3c08a772746253df1aacdc7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/falco@sha256:1d9464d4b159885aadfc29a8effeca73567fc0c9984f57ea5fa1bfb586ddc180