dhi.io/fluxcd-image-automation-controller
1, 1-debian, 1-debian13, 1.2, 1.2-debian, 1.2-debian13, 1.2.5, 1.2.5-debian, 1.2.5-debian13
sha256:61da7f2b310d727659043a6f7b511d519cfb851b05f704cf1f452d990eb3da43
Manifest digest:sha256:2132d596d1925a9d298d8b627b1437482a14ce030da470f463252e25a2627f22
Size
18.22 MB
Last pushed
6 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-image-automation-controller:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-image-automation-controller:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-image-automation-controller@sha256:d05e009a7a35e3de5113b452ad467609933349113915522f3f777bd60dc487cb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:e4a98c6a2711da21feccb811c0e0c3c95d9dba84d429199146248e3d5b3f37f1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:b0eb30be0c753624379be24b839f258b95201fe0f6de5ad29dbd71112aa26731 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-image-automation-controller@sha256:7e645bcbcdeab26c783616890f275c794915aa4735aa97c8bb3b823410560581 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-image-automation-controller@sha256:82066bb0619e361b9f9d4a1cb5a6d46d613c234d80d236da7bf04961e8614bef |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:fe4fd7d506dd80fa6d780ac5269fd00e9fe1001f0e122cae4df1612efd60fab7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:399100289b5cd60985cbbe490a395da7d3b32cab05ef9b7e13156da2c475c4d6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:c903235fb92033e96b49d5e80599f10cb63be49ebdae37ebdcadd49a6a0ae23b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:33e9c5f7dfaf5786f53daa66e4e568b3c173946ecc588c7e2263b32e68f23d43 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:24df8d44a160f2f17058b795f5e14a69d05462af103fc682a7c315fbcb28b9c4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:8c212de64651d46f802361267250c1aff9797720a6800070bd80027c162b4232 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-image-automation-controller@sha256:288a2b2f79284345015ae4b56a09c65aac1e4e37fea5d1c4741c6ab033fb4042 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-image-automation-controller@sha256:4c66c01dbca2d495bbc8b29357599c765bd883f3d6b6d9ae8d8560f515f74682 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-image-automation-controller@sha256:2352d39098d3fcacda081ad80ac259df4e187aee47beca64b1b8a8a101a036b7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-image-automation-controller@sha256:baa570c693341683c8378345250f67d9a593b8fcb5c213d1cccd69cc74f5901f |