dhi.io/flux-operator
0-alpine-dev, 0-alpine3.24-dev, 0.61-alpine-dev, 0.61-alpine3.24-dev, 0.61.0-alpine-dev, 0.61.0-alpine3.24-dev
sha256:f178e8c2b7b622a3160ab9ca3a9f35267cc6013f3dfcd563c2c5c7983fe5e44d
Manifest digest:sha256:9db61462c2ddccd7d1195b719a300d2c67fdb544ac0e6569a8a7f6a100eee9d6
Size
49.00 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-operator:0-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-operator:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-operator@sha256:c4a0e94d52e95de35ece35a48e87c08c9d3bb4eee89806d197e84c17928fba12 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flux-operator@sha256:30d6902975df20101ee27a5bdba12336e0ea44e45cf9f857457071660a95fb6d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-operator@sha256:6cff95ea2326f11b73af4d03901854bb2ddd127a6f97caa41e4cd86a6a7b5b07 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-operator@sha256:3e6091644ed0e279d0ffb6dd27eeb775831aff53e13b6968e871c94bf16748d0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-operator@sha256:19f9c8a4aeb0f9b6646fbf298237239c601f0cdd7992ca8587864d86f5360e73 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-operator@sha256:f3d8448471aaf2fd9a49e892fd8d6b7d5b1405eb00827b1181ec581c9bd6d8b4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-operator@sha256:f778b00ecada61f0f2355ec94a3a095309f6b35124edfd95e679aecad50a6dfb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-operator@sha256:d97610af245ac450be70bd3ad63eecfcf19a5f177e5e7d272576dedb1ec1732e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-operator@sha256:a0dc03676b3bf4424e55742003f36f01fa87c930c136b6c2be4a8b0bbbe2f733 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-operator@sha256:9665ec1cb137b21dc5d67a02ac6d612b343074e24efdd7fdb7fb17793fe8b003 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-operator@sha256:300e5e973feb4f3c1242a195c24d426ec0ecd364cde47bf2005f9d594f1c33f9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-operator@sha256:33e8a95f55c5f03e8bbcd46fdf3e110783047512e85eb6cac620a8cbf3ae9ce1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-operator@sha256:d1ed0b2cba267d2f6f147e7c47a936f8a3b9d4194fbdab531c3725087c172d31 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-operator@sha256:12769e280f71873a853b543b281716fd741e78f6511ee685830292156e4d4105 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-operator@sha256:64c68d880503615e998b3043f15d02e17b546b3c9660d399c70237d8dba77f06 |