Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.61-alpine-fips-dev, 0.61-alpine3.24-fips-dev, 0.61.0-alpine-fips-dev, 0.61.0-alpine3.24-fips-dev

Index digest:

sha256:e4cd649f71d8a78cd3bf48907251b0f79edde34279c647ab6e871f4ea044cba7

Manifest digest:

sha256:30aef3a6685deb49707c85bb6feed3d30b0b3d8f1b26bd500839d6ed2a50aaf8

Size

49.81 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:ac16fea84de5124c9f681fff98fd6f48d34401d5708e7e3a52893aed2f4c9921
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-operator@sha256:40dfe515ff95dc977cb79964df1d0a56262b81ac7da51a5856bc54774760aa32
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-operator@sha256:b94a1ee26aac4578ca3ae716e0e29311bf3345241752952e5fa13368a32ca9fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:0a4e1f4ab060e2eca5c414703431b945b18cfa0396fdd35f01b93a43a97580f4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-operator@sha256:d3a4c50bcad8aead580a76efb5a0aab0f43cbc79d1467c8f6d56b9c06c602bc3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:096e3809b569b5cb1e7ea34d37cb9026a955e3decfe543d5f12dc5247a214422
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:42e27a460acafdeeee28e45a1857e1f27807a0ecac5b4288440aae5703d3c41c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:f879e169a871f2be9fd6ecba625cd0953bc613d52375dd6e7ac6a89ed2d82c51
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:d288e2c2a6bfd395eb52a3ca5a71ac487b8cd2ee9f8ff02ff74db8644a460427
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:00c12942b873f4c498099f177454610a254af685973448519340f36cfcef5b73
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:ed8a895747ab6a9d3a39824dfa71795e06f61dad6e99f44ce1b21388fae6f213
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:cec86f43b899212b0bdf5230e14cd1e97ad7c4b52b4457503d6615d0126ecfd7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:351d4bc7347d7338259d20b5a1eb34a6b2beeabdffc62163af45953a5d44705f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:8e07e6fd489660cdf6b89fe382775787a8d04f9889574c25159a3fbfe8c39f48
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:794bd02de01e72004d76f553f1ff4d665d3766a29ade1bc28063f6a39232af8f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:6f7f00323c8cb988793ebb6c29edabcb30a73bb4b5e6eb034f09731df7124806
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:7a67e494f519ff8c2a563cae0060358aed89fbddb2d0001da9d8975ce98eac9d