Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.61-debian-dev, 0.61-debian13-dev, 0.61-dev, 0.61.0-debian-dev, 0.61.0-debian13-dev, 0.61.0-dev

Index digest:

sha256:f37edb7497b26428e84b0586cc6f39d7f6cc28ae90a91ca229e4ece13b6c0c55

Manifest digest:

sha256:20d302ec2bcdfd3c064b755bb4571a87e77b1f677f4999a48d63278a3d7f80d3

Size

68.50 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:c04294037b5b6ef19b057f242e5dd9bc0f529facd934ea25186c1940c957eabd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-operator@sha256:05c9291972a4a7aa9c00d7517fb3c18afc8dc0130ca6476e8a84c416e194c3ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:4200ce34d127535c56d19c4a09e6907c2231652b36a9512bdcd4da774b6940dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:1af5970a72f3931cfd9ae6d29b583a8b5137ac990b160d14cdbaf91a783af062
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:e2cd970663da8d20fdc00976648e76bd9fdb3138cc84ac20dfeb895c53975e89
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:f59e0b9ffdcdbfeaa76bbf771bd607805b8973649777b01d70a5c384922707a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:449e73dc211f66f0910b7fc17477090623ad7a2b3b92b11e59a2deba3f040780
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:c17c3aedad5d4be9e33e94fab2d8377f5d6399bfd16a64a4a316223218f6a71b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:d0b0caa08fdcd333d2a64b864931d3831437c6dae335bf87de40616d0a0776a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:e65e9b6450a991cde4da6fc2370a1684e9f33caccf55490ff2dcfb9696e27c62
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:7669fae9e6ca346bec8eebff2c52fe941c1e49e42626c903f26ed3836121fa6e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:aabb553ccf2dd7a2763dbbfd621ee0c8722f39584ba1b2b5b082c05e2b6e9f7c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:e5f506ad1f994640df875a759ecb0e670eb2fcddb67cbb3aa93eba8fba73aa9e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:6e90f7c909408b185929e0971fe60fcfa50e13b98dcba22011b32126b5f8aec0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:8bdf1c50a92edd2dc6d48212a8025658c43b2fc156cefecccd375e70cefd270e