Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.61-debian-fips-dev, 0.61-debian13-fips-dev, 0.61-fips-dev, 0.61.0-debian-fips-dev, 0.61.0-debian13-fips-dev, 0.61.0-fips-dev

Index digest:

sha256:15fc593dedf1abc320bfd85f3c12d6124af4f27a426f4217698ec412a0f04dbc

Manifest digest:

sha256:de532252d5d449c06b40e88b8a76c8d02a7ab9f17621d5d1d9b0bef0b5d8cf42

Size

69.27 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:bbd20c9115e767cdb37c0046eb100771df3de65286ab799e9566e27a8f6c3985
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-operator@sha256:b1dd1008bc8cc2b89ebbc57f615a737b1b0102fbada0caf8685a21259c7d5af8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-operator@sha256:e54026619054c77b299c04561ec9ac1a36e32c056a9453dd8abd61a6a28d0222
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:5e7c9806ea85e8223d3b7c9a332fc9010098e3f615a104be182e011e5adada3b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-operator@sha256:649ae64ebae238ce8d78c09d6da98594b2ae7958ac4d6f976a4a74146314da30
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:5c5a3075cbf0651382a00fb805477e2097068e7918abe7a7381ecca7982642ed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:48c1574f8efd6497bd7aa9ac34fc9e13c4d4e7b282946a72aae524d2cb7be792
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:4217df4fb067c722f42c1ccee9ee94b2eec52f78dceaa5ba39cbc6b15553e18a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:2d12bf9f199b01fe0d5cd6aeb231143289a7a5498f1fb96fdec8a858dd569ccb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:abbce7fe9a69501a5a250168f0491b547a60324c8ad67e0bf4905da8aa22d00e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:aef90ad6a9ab853fd12b778277e3eb26fdba5f3675151b8c9d6b28eca835622e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:0618b5b2991c4285d70f81ed9776b8ac42ad393024e387dc1569fcaf7ca75436
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:501732b7d6c4773d3738fa0b6d0abfc5b0099ca493ca1f5653ad64ac3d520e1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:2cc862c2b8c2fc55e24357e033532fc8f356486a5a1b23fa56d21a5e9139c22c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:16a145b128d09e8a9a4c96d41f21f263b8e6111a4e021f8394f42568b4e8ff56
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:9cf659d0bcf6d8bbd129ea4038d7c2533b65b00f2037506d5e4231d8ad38d583
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:6a1269aa9eae0b306ad5fc6a30273a8cf3df04519e858cb307fadf40bc3d29d3