dhi.io/flux-cli
2-debian-fips, 2-debian13-fips, 2-fips, 2.9-debian-fips, 2.9-debian13-fips, 2.9-fips, 2.9.6-debian-fips, 2.9.6-debian13-fips, 2.9.6-fips
sha256:f92b31d1872e1f022181973e944c40e410b2f1f7807f72a92f744baa6c4ca02f
Manifest digest:sha256:4cafd410bdec115002fd6cebb1955941a66b4a2ff82925704aa4ee40f5b73e6d
Size
30.06 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-cli:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-cli:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-cli@sha256:303a2b921f4e0c9608c5785cb1b6c70ddbe2765d76c42e7469d0e5d550510905 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flux-cli@sha256:1fae79d36d8494f853266316cadab65f4dbc0cc859f7ba53b78083326098c233 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/flux-cli@sha256:cad48b71a48e699826636a649e845d159bb868114df321ca2277aa6df7e1f815 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-cli@sha256:3c36bb0ca55a971169c38c99aed3abe87bc51cf79694bfe61fa434829de93bf0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/flux-cli@sha256:ee3589be64eff334d317fac639575200230eaa409ba09f85ebfcffe1eb242766 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-cli@sha256:0464c7cd797ac184b9dc30e556c5a11a5040050de99792e2a2b36e6b4dc850fa |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-cli@sha256:500c8258b708c324f006d6a64760f0accaece7e485aa726030e0fccf8d27f17f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-cli@sha256:e0bc0891edd50469bad47f03595625a81e6a1142bdf395de71c0639445f24091 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-cli@sha256:5caa86265db3ee5ede998615f13b0c4d218d41c750b4c03dca6c42d2e49f2337 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-cli@sha256:850b4f271228c920fd95635b94e667be437fead49cd8853596e627c52d8d5aa3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-cli@sha256:bcc058b6993ca4d2d80885a4063da65a3b5fba5351a0da428e45b1ba215c6afd |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-cli@sha256:093b26549eb183fe965c0a0a17fabf8612d700ca171db292ab427c9a717030ce |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-cli@sha256:303c39fa5aaceba3ce86d890d873ccbe4dd8dc82410dbc3ae19fcf9997a755d9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-cli@sha256:21dc5090a654c44646fcec651438efa6e93f7c1e4ef2d952cc5c07be36fc988e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-cli@sha256:9013622dcbc2901774ca04f6f7d741d1687f3ed9ecd5b508b3e38fc8699c177a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-cli@sha256:395dd9554d7b4a133eaec4ef0b6a256b6af26bc2c6e6281da76d564df97dc6d7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-cli@sha256:d2e75dd0c00548026ba96a4e036ca7e4e72ec59609962d6be5c53935fc2a4705 |