Sign inSign up
Source Watcher

dhi.io/fluxcd-source-watcher

fluxcd source watcher 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.4-debian-dev, 2.2.4-debian13-dev, 2.2.4-dev

Index digest:

sha256:43057626887739b6300f398c03b12ed503260c3eafa2d14d704d6a3291ba7cf7

Manifest digest:

sha256:0291ce49dfb93b67f852f32d5cd38d3079ef6a58a7261e179660418bcfafe70a

Size

48.90 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-watcher@sha256:8d3d3d58915c3a2bebdc020132feadaac080499cace47894244cc1f96cb37567
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-watcher@sha256:24d1ef86a5f9106f222c307bcce793747d22904150fb2751b67bd9bc18fe1804
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-watcher@sha256:cde3976f231bbcb6d5369eaacbd0d1620989287d7b197e78be7597f48ace7e2c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-watcher@sha256:07cc1ed24c64032c1ebf74cbeafc00223a435f28f24c51afb6885c26f3f6c6fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-watcher@sha256:68ea2da3872171f3c836721daf8e5f3b801268ac824f7b2828f2d3151d7f0163
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-watcher@sha256:df91f0ba2c48155545a761cb3e2a17c58c0c8c64e460db2a777044290a817829
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-watcher@sha256:df70ee52cee5cd93ca67f22cfddb0525ca8d17ec935d9a746aca47be9563e833
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-watcher@sha256:6917baf333cab4bb012e7152a947e1a9e15c9d5344433cf42d334459df60186b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-watcher@sha256:cfe5ea2f5c83b39efd0bebe459d677d1ac340f90e3fa1d9eeb7913406bd9006e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-watcher@sha256:0df6dbaf55f73fbb15f5b7e2398a137c86daaaa628571cea8e2cc4d6796b32bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-watcher@sha256:bacb6a765ec35f5bc13b84bb5c47ec4a790f3cfe09fbb8357a22159c48d5105c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-watcher@sha256:c201b252b63aaf868eb9111006bdd6b4bd28a88bf11b39d8df4d011b90cc71e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-watcher@sha256:bfb61ac657e87c9a4006e5236a5b9bff56df8299dcd043aaef1cc6669018cb5e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-watcher@sha256:dd3f3620d22a7b95972ffd181324fac851044b962125529ecdb8fc952399b6ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-watcher@sha256:6aaf38fa1fd15e47df435654b4f39fcfd383ee60ac7a75ccc9bba080b6ea2848