dhi.io/flux-operator
0-alpine-dev, 0-alpine3.24-dev, 0.61-alpine-dev, 0.61-alpine3.24-dev, 0.61.0-alpine-dev, 0.61.0-alpine3.24-dev
sha256:c391b453fb245fbee425010f1d686d9b199b52609b47ccff29ea809a040d9e30
Manifest digest:sha256:b5805c337be8d11f5f5303f0ec365fdae0216ee6989ade64e647bc3fc295e318
Size
49.00 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-operator:0-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-operator:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-operator@sha256:f1b6c970fe777a25d13ec09e6c2ad03ca27e1f04ce1af6f04ad9713c284d9cf5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flux-operator@sha256:c8c29c2329259da9f7dc98744e4f86fad5e85e7418105c4e087208917264018b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-operator@sha256:1eb0e10b24abc9ca89ec2435dca39b5233169244155adfb6ad906cc5c258b3f1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-operator@sha256:5576d4d92241f5007d670633df58aa567beabe75cce691fab04e7021cc506185 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-operator@sha256:741d982b808416edccde194e9578d2bf2b6f51f8fa3e29db45d987106a179fe6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-operator@sha256:1b8414838244ceae51519a7ef933032ed381cdba37c4c597dfcafff35efcb3ba |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-operator@sha256:aada7caf82932d29946753286060cd9326d5d575cd3347ef8e23fafdaf6dc62f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-operator@sha256:e1f14faa194781b2443c70b8cf674fe44fa10ab808a52221bca7011619c617f7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-operator@sha256:4d240ca5ccb5ae873a164b6c09fd1e2e36894138e32c9986b0768054212daf75 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-operator@sha256:7a9d00012b7f0fc238ade140429e132e1c8418ddaa70696da3c6b162bf372e13 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-operator@sha256:d1c70ed922938187350ba657005c0f7a74ad88e8ff87edb2c6f25ac6b6f8d26d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-operator@sha256:57bf1af8a3b1e9d1fdae47531c527efdd8fe84e17ffb137f2584bd280eb82de2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-operator@sha256:e16d7bc8b67d7f297a045b5d02e6cb8957805cc9076525d5061482900dfe301e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-operator@sha256:bcf95be5082614ba536f8f91d812d35edeef8292050c60f09ed28f1b26b2bdf3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-operator@sha256:1cbf4051391e1f8874391103415dba20669bea42737dfe67ff3e1e3e77d4e950 |