Sign inSign up
Flux CLI

dhi.io/flux-cli

Flux CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.9-debian-fips-dev, 2.9-debian13-fips-dev, 2.9-fips-dev, 2.9.6-debian-fips-dev, 2.9.6-debian13-fips-dev, 2.9.6-fips-dev

Index digest:

sha256:63d6b07df2b382d20dc4ec7682ce335a9ed75b611ac920cbb64059e81b74c0c4

Manifest digest:

sha256:e910caf6aa35053166fb47b508b5a32514c8c2f6b47908c2339830212cda7c39

Size

65.67 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-cli@sha256:cc5c1ae54358ccf7005a6734d8861d67dd29a66133bf5dc841b540005fc9bd7e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-cli@sha256:cc6a3f2ecde967827f707b2c78d85ad66a759636d59a4e93768e54cfad74fe32
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-cli@sha256:afd0fc496f8dd0882118b695b7552b4d884dd5ab5a6d99e9c75a29fda186ec60
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-cli@sha256:91a21237e1117c02e708a0506427d3f408f60bdd0366588ca79dfb873d25ed24
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-cli@sha256:667169a2b0433ccb025a076da7f0722b2a0847b908b7af3bd55cb21b2c81ceb4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-cli@sha256:646bac6ffd1408efe0bf6b2e91fade15649568938e0b300ecbe4a5f14b2690d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-cli@sha256:29b638078934172c41eb82ff802f6e602c140450d8cc23c2188970b85470fbb9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-cli@sha256:8e4a0cb1beda1253e8f1e561154bfdf521c12e405d44be8dd4cba6eae78766bc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-cli@sha256:d27959c7ac1573361fb3a5af4dacd2f976240235ad2d8de251fc841b2fe57c40
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-cli@sha256:99b562c601d45e5a2cee6d8be2ace246a58ed32ac1776031aa2e97406f12231e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-cli@sha256:d40c15f6e84bc23b1a8fdf35825ca912b69d6bf8ae839ea21379e13f0c628652
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-cli@sha256:18756e9d10b9b6e8bd849409bdd105962e7bcb9d5c8c99c19abf79d40e751d9a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-cli@sha256:8bbe1387d4263b9d53b439f75f68ef2ee9aa43501dbb7c49f410053c75b81b09
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-cli@sha256:2664f7bb46531155ad42aa20d7b0dace843c2e4fb78cd35c547d46f3ae92ff13
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-cli@sha256:3b149a56e52e8b6e597b2a506cbb442d1c6c8af38f45915816b340b71fe93187
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-cli@sha256:6a2c602fafd2cd250b265fb7968ca705e4454511c973e54a678c23b0b52beae7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-cli@sha256:3155e85b02ffffbf664c5d65ad82d563255adda855ec617f9a27826ab46009e1