dhi.io/flux-operator
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.61-debian-fips-dev, 0.61-debian13-fips-dev, 0.61-fips-dev, 0.61.0-debian-fips-dev, 0.61.0-debian13-fips-dev, 0.61.0-fips-dev
sha256:82178eaf8a93c8437842768ca25ab382105d3fcc07be5a8f3fd33c0443d6552d
Manifest digest:sha256:9897b5a2315309b58d7e40f7dcb5da69746b7217219854acd3bd0c1adc6e2b0f
Size
69.27 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-operator:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-operator@sha256:3feb5275c5d4e3432e7c6faa058f6be5ddd771ed87d385b2b37bb3c89153deea |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flux-operator@sha256:d4268440faceeb3e9c16bb011bceaced9101114a073664c0957c08102b4fb39c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/flux-operator@sha256:a3669a5554c27ffe362c71dccecf041e5372696669c72ebbce9a3be532d1d0ed |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-operator@sha256:48414a38c978e4ae1ed9c2910b6ad80723e74ef4bd0c16dd8f06c05fcf8cd297 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/flux-operator@sha256:5ffd7a15ded06ec87acd8bd660a99d8704a50b93a8331afb21ab5df547449a9d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-operator@sha256:eacddc2de9aaea68d7577a32b337d849451f55a93fb97273aed91fcfacec378f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-operator@sha256:526bdddcf6672dbc20f20f8b7147b06e17651c933eedf2b58f5156975a592920 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-operator@sha256:980971a2699367694071c642d50018400b46c870e894d2d8e2ebcc070aec4669 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-operator@sha256:6cfda5c47f624dce5a0ff6babe4e7c315d1ed98203349f4e5defc409de11c03e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-operator@sha256:95609966c97b3e6600eec9cd1933c7680b56a899a4e5f3fda351cf977687b723 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-operator@sha256:e20fe37a8df8ef4323572ebaa425952f5b50091668de71dea3a083da71283f06 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-operator@sha256:7ce79fc315f87d04666c2892f43410250d1ee5f4c63337568a611b862e512055 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-operator@sha256:3f4d9414165721757d5cb2033755bfe2ecba00d18af813d8c5c9e2fa05678a44 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-operator@sha256:02a971dea2f651222399611c1517892e7196def671858f469974bd3d6b677486 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-operator@sha256:b90bc5b74bf04edeabdc050bf2439646da7f91926a8f575a6523e506acb83f00 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-operator@sha256:35d08cc06b5d312bca85e3df7b076d9002505278c233aaec99f0f0f1ec11c627 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-operator@sha256:82236cea4f7086a6329657fa834fa6e4f8f862fcba0bb37d6d153dc550136170 |