Sign inSign up
Source Controller

dhi.io/fluxcd-source-controller

fluxcd source controller 1.6.x

CIS
linux/amd64
debian 13
Tags:

1.6, 1.6-debian, 1.6-debian13, 1.6.2, 1.6.2-debian, 1.6.2-debian13

Index digest:

sha256:56e31d44fb3f1006c634b1b3e425460e252e576232fc8b097d05ca1748420945

Manifest digest:

sha256:52bc5fd4f279cf24c47c810e8358bb6d36f4c1e9d8f11ac482c15937e5b5ea8a

Size

27.10 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-controller:1.6

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-controller:1.6 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-controller@sha256:2616ebfd0c490f1ff7b9fa8470550ca36fb641223d74773390f3e3424204d08f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-controller@sha256:e321f03fe9038974b3d09b7cd71f6686927d46230d8c273fb396fc5126ff24d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-controller@sha256:badbc2493b4cbb30c99691317e3549f1be54c3a551bf224ae69db4a0bda9584e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-controller@sha256:799c337644f726fd5579928cc6cdcd17322f2b63727032cddf019077d2598b61
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-controller@sha256:2421619fdb9283f878262293a9deb67b609bd4332f3ba4d1b7af4ca0b91d1365
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-controller@sha256:2989b6a8cb07f831af50fb4b05453e500224a510cd9cfd764fc11ee2289e9eb2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-controller@sha256:7ae5a3e8a97c18e1c5ea93bb4e6861df457fe8f1a07c74e211eaf5618073b8aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-controller@sha256:c4e4bc0f48d0a318cd43c946dc7ee42c1e59065dd8847ce95715ae3fce51d742
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-controller@sha256:ce5ad317a6521e62e38a6d55f676941863617afdc276d755cf97a0abe9348f9d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-controller@sha256:45b413fd56208119fe7df3fe5e22b2373233bcb133ccf33f0aff98b17fe3c4d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-controller@sha256:451b49c75d5ddbb37f634d503ebdb5bc8922a5f2da9384e12b156076ccf924b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-controller@sha256:01336b0caa8f538ac2922ab5320480a4134dc6e03958b46b102daf6a8b5d054b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-controller@sha256:1b64af31df1845ea5ac0d6b0451fb3536a089e5c764033c0671402d62d52c06b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-controller@sha256:d3baef48a5be1bc65bdae1fc3087cbd13001c9c0e43d80024d06f6d3a9b8aa6d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-controller@sha256:cebd02bf6a4a22b39d72d003b5aaf8bcf8b3c34d397f8e018d9b73a559f74bef