Sign inSign up
Source Controller

dhi.io/fluxcd-source-controller

fluxcd source controller 1.7.x

CIS
linux/amd64
debian 13
Tags:

1.7, 1.7-debian, 1.7-debian13, 1.7.4, 1.7.4-debian, 1.7.4-debian13

Index digest:

sha256:1a63a652ffa619463ef0278bd21ad2bf3f49a3aa71970d35f88c08ce2d7618a3

Manifest digest:

sha256:12590871f55f1ecb6558b07784d6f4d0a5868ff5e9ec7484e528dc8b6f1dbaad

Size

27.38 MB

Last pushed

13 days ago

Vulnerabilities

0
0
1
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-controller:1.7

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-controller:1.7 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-controller@sha256:34c594f0b2f89d5df892049c5a87083d55596d083cbcdb29bb2ac81365d38e02
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-controller@sha256:1bbbdf6e6c30bc247f45eaad17f4c6adb7650d1024ff2594d058ef2d7f87e4c0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-controller@sha256:a8692a8c16637df8998d53be0cfd001ea097d6f9847a133169f9e4f54464a240
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-controller@sha256:22edaf0aea25b881d582ccfb29c786ba6792b0bb0ebf2cbd134dee057c3d1356
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-controller@sha256:c89b695d9b90f674d602f23558c554c83e9ecc74f86df73cafb6941ed181a46f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-controller@sha256:71fe331d01db889c9ccc3c856e027f400ed73901e9159e33795b6e2ef273ada8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-controller@sha256:a22090b8966dbc0e6ca88b98d94fe013cd4e50e7b4e378ba0105635ab2b8faf4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-controller@sha256:3bb4e75fe522d412eeec469293d965f29de761c5d1d40805c5464f19caa0f2f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-controller@sha256:984785cafe26c7c72e81ec5129482740b13d48d4f18c48115f419a301068e4b4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-controller@sha256:0c9459d140ca3c5386b325504a444cff683bb7493a2f06c63130b92492ff5763
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-controller@sha256:f5c81e831922ffac5c8ec7cd01e3fd7672d4b5d5aabaa5579bc2fb3d21abf600
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-controller@sha256:96e8dc5d88fd952dad6354cb3be4356e9e666f007998dbc5a17282a95415a3f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-controller@sha256:32e02feb05bafb421625168367d865793e702033b7592c699944af8994577fc6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-controller@sha256:00f1640305b24472b61c4b3da6340d8047af51794bb77eb5faa263f502966dc6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-controller@sha256:bc29f5cad2f5dd6ed4161364e8981debfa2066c78a6db752069e6ee809619b19