Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.61-alpine, 0.61-alpine3.24, 0.61.0-alpine, 0.61.0-alpine3.24

Index digest:

sha256:636068dff64a6b73d69ae33a000987e9c4380cc7ed0488e9768e9ae40ab73ba1

Manifest digest:

sha256:9dceffc1dc98c7d963ffa804a18c3541fc51817ab87bfc1e5927ee5d238c6fd1

Size

23.03 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:35f91eb56efa0e736134302dfa032711fa388f94fab35f9ff522ba757ec46ba9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-operator@sha256:aa622f7cdb1ec8eb6d0909d042e2eeaf7c741cd1efafd6e22e7380f9a7e22f77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:c50e38ad68ee8ee887333a52663fbe8189e7859fd70d7c1f80b72253f54e6d30
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:848313d5174bb557de44b3c6d8f0168a264a24d74d48f01989f35a645d0faf73
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:95af4c6b1ecd03b51cbe14769b54063859e55aad923636de5cf6832ccaaed86c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:0974e11124fab3a3760c5599e58981c1736b16c1abbc3bb7ae402dc19b7dde60
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:d60cf793ba73cc76f7d8ef0e7d48a0e8db95067a000211b86b9c869a087dc221
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:c588fa4aaede9b4472af9ec6faf2e745c0b64f0bbae16aec61b18d1820da06da
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:565b2eacd5fc0f120bc43178a871116c75e8a189dc8dee5acee3aa1b465b533d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:b88858641f617c1fa868a808d4c0115f84a1ece688048120dd68b1a1f4fb348b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:84313c69ab9407ef5865f8e3ac0a81412586797e12f27c59563ff491c6cbe4bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:b355061cdccafae90ee9ea7a46dd239ddea6244feab97516e6741e895149619f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:be0985a3f17d1eeaff5c7393635cf1a78497959532eea340252e39d520a9e6a3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:1900d3b74dcaf8675d75d24817f351b2b00ac363d521714c469569782864f3cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:2d66fdc894aaa554f08b4d7c5cd4fb59b7a054116881714755d44e1fc123d36c