Sign inSign up
Source Controller

dhi.io/fluxcd-source-controller

fluxcd source controller 1.7.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.4-debian-dev, 1.7.4-debian13-dev, 1.7.4-dev

Index digest:

sha256:2385638d682ebcbdc1ad649200845aac8d1abf7691d615744872e32562397a50

Manifest digest:

sha256:4f191d5a4c3158a025c2a9b9c3b7022b8460b3c72eee685cd051626fa4ae4b4f

Size

75.43 MB

Last pushed

11 days ago

Vulnerabilities

1
5
3
4
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-controller:1.7-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-controller:1.7-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-controller@sha256:65905ca05aa4bb72694325dff52f1638be8663dfb8efcd4e03ed35a8e501cabe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-controller@sha256:c2a21f37b074e3169fa57fd51ef71836d2a92e451371b40c79eab2b03d9b5013
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-controller@sha256:7086c6b129030e146e2c48b03295413b56390638e71ae1bc65b96899c0acc046
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-controller@sha256:b2db31d87999b138004a032bd7e23d2e592dd13ce2ae9c9dae330744537ca74f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-controller@sha256:30e9ae4585c3d464c79ab2f939ec8bac9256c829124408458246fdde81bb535a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-controller@sha256:70e7a942679e736f0a3ffe8c938a3857c31b61916e3133db0ae3c0b6f7056ffd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-controller@sha256:ca3dbcc75874f5ec3c37b1a4eedd4e312c5a707c87ab60122ef3a78000d7099e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-controller@sha256:4e72e5814fb890f71c17be9c8f55547b5a27b633b81c38075f1f062ae8e48330
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-controller@sha256:d1918695b494e397a08a953ad6552631a827654c725bd05b0a9ad2f98661d81c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-controller@sha256:a7dcf3bb76f506209ac4a974f9f54e015fe9a6b55df670ceedb1250a37c6af0d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-controller@sha256:fd9669febd1380ef472112bcd0058a037d573312098af4939a7846e57fe898ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-controller@sha256:886304fef38a02b582121bbe93ac362bc24c7d6ac8440d24e3399fce19417ca2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-controller@sha256:6b1feb6a147980662aae02666ec1a27f8314d4c4ad67886a7908eaade3f28283
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-controller@sha256:8e335260594208ffad11d5181a083f1e2b5756401ea778bc9ddb4fe0640e28b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-controller@sha256:85f44c167ede3d91a00d73526be7c634068e50fdc7fbc8dc67d74689457f8b26