Sign inSign up
Source Controller

dhi.io/fluxcd-source-controller

fluxcd source controller 1.9.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.9-debian-dev, 1.9-debian13-dev, 1.9-dev, 1.9.5-debian-dev, 1.9.5-debian13-dev, 1.9.5-dev

Index digest:

sha256:f7e21fac7683855bd1e0d96518a6f138fc34bbc9cea9481581c53fefeebaef22

Manifest digest:

sha256:031baf7c99d015606a00de4a24851881bef44d281eb468981c70e0c6a9ebfc26

Size

76.29 MB

Last pushed

10 days ago

Vulnerabilities

1
5
2
4
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-controller:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-controller:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-controller@sha256:5443187040887a849732c70f49cac65786a4f13d50bfbb7f98b3e8d27fcf98d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-controller@sha256:7e6a9f5d35cc5a368870a934991c0eac2a61cb013c19e11b4851c9740ee331bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-controller@sha256:a80516126193b38a9daee089c6ed2763c056ba22ebb449efa4ac22b3f5fa0b21
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-controller@sha256:5b72c1b66d6cb1b4e40df2d4023b6242fa45b0109f6a5ea32f590e00fec565d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-controller@sha256:6bd2daf34a7ce473f01921ca915e0bf5148b5d291d93e5536fa2dcfc62701fd9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-controller@sha256:c92329763b34751829e9949b7a83d008b6542f53eee07b3f6752a2ec42898a4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-controller@sha256:3b7a53806214fb5f5dfc91e294d7cd15f0598a0f11c5858bc6a74dc06444bf8f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-controller@sha256:33462d54c85cef169c8b21e1b55c7dbed260f2b5903332ae541d2bd25a40f877
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-controller@sha256:26e47c3b170fade833d3f8008411a31c35fed634fa755bf3aa4063ff1228ec9c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-controller@sha256:bfa48d34647513e043ce210390ae233e85978edd59a7490aaeab7c83b7fb8cf0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-controller@sha256:08027ae208eec223a4038f617d830fdec640a9776cca32e6d8bd898d85d714e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-controller@sha256:c27f30a92c7af4bda8a4758157ada6b8bdbca1dd6e5ec9275cc61e495aaede0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-controller@sha256:fd1963a7502d39924b3a26b210763293525df82fb6995688948ad96c8ccb24aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-controller@sha256:459fff6e6d6f8822dbecfbd85a90a09c9fe2531aeaef2092a7fdc892a423390d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-controller@sha256:e648c0a124973fe0f5a63be817922c7138d265a8e4e72464ff97922a20efb258