Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.61, 0.61-debian, 0.61-debian13, 0.61.0, 0.61.0-debian, 0.61.0-debian13

Index digest:

sha256:07266a68ee203b206a8687063b5a5d5b89d5eec569cb7bdd349f764810f1510b

Manifest digest:

sha256:2b73f6de97cd8d2feae028774db2c8e1bb46aa701e9f42253a1f69eacc33a564

Size

23.30 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:8e14253bc2174ccbd77238c21d49740cb20e6aefb7ff689df922f0dc2876560f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-operator@sha256:bab8eca9556c95f8302ca78f7c6aa7e1cb9c17eb8ca5b895badf953653e77d8d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:4ac6d2f2c879f54108fdf154d817efed281ce96f2f2a1e9ff528575d93dfa7e5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:3c1236a9e9b714d9b0cc3678f3baee77de0bcae659cd6fc2ae58ca464a0677d4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:6cf5d19293f39790304ac688e5bcd0de16c001a773e6b362f07810689220b01a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:9c2dc75552c941cf69d2ad9bcc52ddc73913b14372f8f1d6880a6e0e3a1bd765
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:ccfec41e3fcd55647f1d4304d6ff46a3d1c3138b0d237dce9f377177703d9602
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:da77b5fe5e941bfbafa11281199d50bc03118572a7103793bbfaf6b35f5fff4d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:48f5b5c954477b0e4905ed6c8f54c76b02066f1ddfab4c586953a2a9e97e9648
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:5689bae4d50bfb56993c8549c6f0bc84f389020b91f1074fd972128a013997fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:7f146d82a0703ecb7e3da4e9ac224e37ea937573c375033859ff18fe9223356d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:f205b5c4fef0979c10b83a7a54fc3d61d163b94ab9568f1f37d465dad57846ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:6a46d7a21112ffe2c6de6f47a1541343f4be4262ca87979e0d32e52d4569e577
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:a32e01028e76b61afe6706b23fe686467abce6eef82923ee3cbe7f2177f38aa9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:6954c045d6d9438b105b9dcb3c691b36238478f1765eb2fa333079130d6ca42f