dhi.io/fluxcd-notification-controller
1-debian-dev, 1-debian13-dev, 1-dev, 1.9-debian-dev, 1.9-debian13-dev, 1.9-dev, 1.9.4-debian-dev, 1.9.4-debian13-dev, 1.9.4-dev
sha256:0820bf92e72cd76e73c50d0f9ba3ed25ea33a899225181c40bfa59601a1de25e
Manifest digest:sha256:504c64294dcaba5ae729928f5f42633cc365a5affa64fa152d52b7637aef14dc
Size
65.19 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-notification-controller:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-notification-controller:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-notification-controller@sha256:2326dd51796470c61db9e94f9c607f1215008cd0a55c667dbe19028c18a869f1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-notification-controller@sha256:612b0c5fcf4e015e24ce20fb31e54b4648a8683d1bd8293495b13b4b3f78834b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-notification-controller@sha256:64a4ba4905067aeb578e22ab2dc6a82eedab27bd6b75c9f66ac6945bfb9bdb33 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-notification-controller@sha256:e9696b029a5ba6175ccb8325244bc243ee0ac255c6e889db6156e8f777819170 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-notification-controller@sha256:d1e02f7988da73d48fd28163cde4b86c8e79bec06fe8e3fa49977f8b521a9d48 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-notification-controller@sha256:8d968b4cd20a34a8bcbf0b99ada0959e62e30fc7e60ba78bcf2aade1e07ae3f0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-notification-controller@sha256:b6f5fa713d8546490b7634f1b28178062a970466f971e9b400e55e766346a424 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-notification-controller@sha256:7b5d31729023f7d521ce129ef7a020d12eb68e924f5f99112dd3d382e3e08f62 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-notification-controller@sha256:c9d65c688b581caa081a2cdc6a0d4cab53f0b1bdfd36626c399fd31e2fffc763 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-notification-controller@sha256:e415ea12d1461c0ca4e39f3e29eba90345d1636780a53277cb45ffc5be5fe8b0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-notification-controller@sha256:862a7b0a2d286fb58f2afcbeebfd4457c34182fbd013923dfef52362b616c707 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-notification-controller@sha256:7f409cf77e83ed5899ed058ecc595e61053b2bcf9eaea3341bfdc5a00307c69d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-notification-controller@sha256:43f1fccb17d0f00cbdcebd09c20f511f25554ed37c887c0792ad42665e3be056 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-notification-controller@sha256:3e38d583c191ab4bca184a08e78694fd6bddb5414d58678fd2a245457f1c1095 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-notification-controller@sha256:e58a09753186f6aa906294c0004c0bfb58c33d7ad44646941a53f3f819f3f350 |