dhi.io/fluxcd-notification-controller
1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.5-debian-dev, 1.7.5-debian13-dev, 1.7.5-dev
sha256:3654f7f6e3ac9d5ba7a4a785c19356bea29180eaac290acb5641065e62916b0d
Manifest digest:sha256:23e40f9c8d33906e132cb54dc55273ca089a67beee3dac40b3c953630ca8bac3
Size
63.59 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-notification-controller:1.7-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-notification-controller:1.7-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-notification-controller@sha256:422f43d1bf6ad7e3c10f174c3a2628839dbe10b245cc6de5368e58eb3f8a55f4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-notification-controller@sha256:e24cf3861351b845cef475117cf8d831d6dbe7ef0b0345d44fdc0baeb4a04aed |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-notification-controller@sha256:ffc15b22b1fca8829ab6a357b05851793ee619b8181851adbac7993217f98bd2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-notification-controller@sha256:2086f88b62233719b0fcc54f7754afc21a29aeb01e2c9b5e0c7a546ed916456b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-notification-controller@sha256:d209314934bbb3bc9c2aa90cd4bba19e6d139d9f6655022d1a52f2b88ebbe784 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-notification-controller@sha256:b806b9ad7b5672bd3a1300e8fac2f043a0e37443544a0e6b9ff7aa1b3be48e2f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-notification-controller@sha256:095f9984eb21e0b1f9af382e6ec7ec5c741d991ac557f3f8499a8dfde937e987 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-notification-controller@sha256:bc54a1ebcffcf5fbff9c0f14242a52b563a5a1456b6e4a741771b08860b97b6b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-notification-controller@sha256:2616574c7c0670ddd7d48b7fffb4c5bd7dd53003c5bc990c3a86805b88f4cdb5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-notification-controller@sha256:2030031ccd5438a80d6a0600d171d5ffff9b9ab756386e67d9cd5a7315bad64b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-notification-controller@sha256:20d26a5bd2e43f5e3181d4b5c9e56d8fa7d103fdf470f052c909ef7e85fc3144 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-notification-controller@sha256:1ce664af8f696b70973a76bd9c23655f9acf3c0011daf2ec5629ed2d9afb8f40 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-notification-controller@sha256:148d125fe487537977ccd452756579d4db5c2e84424a3be1701f13ea19e98626 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-notification-controller@sha256:ebb3f64565ce3f435c00c946c5d7af988afdcec19f33994dcc1bf0c6f118fd9b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-notification-controller@sha256:c6b44cf05f3bf0f5b3e7f20e96dd12fbeae0032a47aae95ea267b7cd24cb9472 |