Sign inSign up
FleetConfig Controller

dhi.io/fleetconfig-controller

FleetConfig Controller 0.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.3-debian-dev, 0.3-debian13-dev, 0.3-dev, 0.3.5-debian-dev, 0.3.5-debian13-dev, 0.3.5-dev

Index digest:

sha256:a90a9de0e295de1806ce9b79c1fe055e7fa3fedd19d1253219464d060aa8643f

Manifest digest:

sha256:a2e1b193ab245c4fdab470432c6b776c48374397aa1f88ec586ec62b32822460

Size

89.91 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fleetconfig-controller:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fleetconfig-controller:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fleetconfig-controller@sha256:4a213e116f5803b9a8b1889b457de23f33ccba76b17a05bc55160ffe4f7a117e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fleetconfig-controller@sha256:ac32c0033310b75d67f4920233f7ae44c91feab7d02919c40d7a9ca4e2e2709f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fleetconfig-controller@sha256:637abca3605da37360fb54b27ac715e74bdf8bb3c8a35c3835f3f2f0824b174c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fleetconfig-controller@sha256:dfd48aae71ad7ac725c1f14563a27d40dbdf9a578e6dde3c36d9a58dc2f15332
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fleetconfig-controller@sha256:7e6ef521b82f855b1cc4d8ef3c98c9895bcfbf1645ba1ca72b0e1de1207da4f1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fleetconfig-controller@sha256:b95f840c22128627e32dd8e84f09ae61fff6ec08c1adc2be8ac09587fd04a903
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fleetconfig-controller@sha256:f0a2c25f4c4823a48fa78a9bd19e9a8c4214acf741176776941b9f93c5c46be8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fleetconfig-controller@sha256:3615b63d80a203ef42913679370c4e0231932febe4c42c116a361e4da33f332f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fleetconfig-controller@sha256:e721b9d1bc580bcc0b487f355f9590e641115aab12af32c9a79e71468c1b00ae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fleetconfig-controller@sha256:64172af5ddc1dfa67851d5c2f8fccce113907125b59b8fc4a24cc777a57aca71
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fleetconfig-controller@sha256:9224b7b65a975657ff2cf32dea66b8bdda05678debeb9f9fe09e6bd820df7e1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fleetconfig-controller@sha256:89498f04a9dce58dd2d2555c60cf73cf249146f6daa6d24775cf3eccaabdb2ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fleetconfig-controller@sha256:6d5bce53166306c8a78654b7f303a415f96f7a1b9bd874e45af648d2afa07b3a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fleetconfig-controller@sha256:4309de1577371b7a357bd4687298b57b29edc03f2bbb255a1ac194bf89805379
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fleetconfig-controller@sha256:1d81c5743375b35bb2f65700eb997bab1adc38d917d2e2dc33ba5e7acca7f167