dhi.io/flux-operator
0-debian-fips, 0-debian13-fips, 0-fips, 0.61-debian-fips, 0.61-debian13-fips, 0.61-fips, 0.61.0-debian-fips, 0.61.0-debian13-fips, 0.61.0-fips
sha256:a998001599daba2cc9c579d8dc6672b22ddd035f3d6f6683f6c8035b7315aa8e
Manifest digest:sha256:98be1d31d65879459e9fe6cccad2efaab61281d95d5ab8776aa13c83ac4dd6c6
Size
31.52 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-operator:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-operator:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-operator@sha256:442fc9b1dc58241b06310709cfd5a19fd44de3f9235b99397f96099602ec9b5c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flux-operator@sha256:d249ca99a271370cee71c03693df44cc995e9263e1aa21c85077972ae0327981 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/flux-operator@sha256:69946146e98a1d49c6b3291a7c8d43b551dbe2aa3dd7d83066a118dc6b0df530 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-operator@sha256:9424d436a388e44e6c11f67c573b57bca021b9b68fd30bc52c249a0cf639acd9 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/flux-operator@sha256:30d591eb532c5fe61a86c7a39c2f696254d173bbe8640f8af208adc206a04f34 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-operator@sha256:0de5bfe6c679a713eb6cbbcda3032f6dec5c90eb37b36a021acf3c13f125dbb8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-operator@sha256:96b5cab8333cf0ea0e64d91d3aa5fa43ea4be638549e7e8863316e381c3cad95 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-operator@sha256:05ca68f2c07ad89cd3839b1e6307e8b89fcdd981a86f795cd5227240945f6ea1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-operator@sha256:47648e358155d1b2b16387bb6d4cba441bdb1e39c60df1eda92d754d0222f80c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-operator@sha256:dfb6f761a3591b59e2dea95c42028f227d183dba11a814c737136ef8379b7f73 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-operator@sha256:7f4404d7db6cc0d68caad04f116e4fc6d6cab9ade0c6eea0bd69892e6fbe6e7e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-operator@sha256:73d9aed487d4e309d3ed3fde9efad871508e3f5a4d1d6d55b58215b4bf1b677a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-operator@sha256:bf538442c6c6a7049603c0d987984aed7a38ecdf578cfeb33b9ed56eef36ad9f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-operator@sha256:2b435f55ea0ccab143fc7ce1f2cd4e36a44b1ceb92f0118cffb4af249337c1ea |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-operator@sha256:1215f9d3122392763f889b5bd99a76da15cc596a8fc71ebf2d7a82a714813508 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-operator@sha256:fa2ebd674cbda83b872862b5ef85c30fd47bafb79e5c1f1ec4330e1a5684a9a8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-operator@sha256:962afb4bca36e6bd1d0aff9631a684ed84c83dc10a4a44a082de254ed1f97df9 |