Sign inSign up
Source Watcher

dhi.io/fluxcd-source-watcher

fluxcd source watcher 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.2-debian-fips, 2.2-debian13-fips, 2.2-fips, 2.2.4-debian-fips, 2.2.4-debian13-fips, 2.2.4-fips

Index digest:

sha256:726ca0b3be56c5f6e56a5b611261601f9bb3869dbb3d1766cdc8a4a3402535e3

Manifest digest:

sha256:5f16c96bd5167994bbc18f0172853e1a1a7c2df3737a3191b4229d78b9c02bd6

Size

21.77 MB

Last pushed

4 hours ago

Vulnerabilities

1
3
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-watcher@sha256:301e75e1b91c982f555ad24e804722e2ff651c47ae556fa3d4545a2b8a7dd1f1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-watcher@sha256:25dbd8fc7cc648cc5917c2c1fe900470eb2db7f82856f338ba57018e67a116e3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/fluxcd-source-watcher@sha256:b124d7dedf35cefbee7f3b966cbc1c3ccc55bd2f0b90157c1cbe826685c582bc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-watcher@sha256:680b011e15dbecfe180dc849409bf89c950e6686ae0d707f77b1dbab58e1ed43
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/fluxcd-source-watcher@sha256:4be07d411f6ce66d122efeb19653be198dc2e9420cf723e5b9ee9520c5954270
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-watcher@sha256:992a06442e091d0a2760637785441c4d485f7867fdf1f8dba6edf854ae77054c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-watcher@sha256:6312cecd05819e9a3477ed62f2fc125a6ede542c4e33be4a22ed60f44cbfc5ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-watcher@sha256:0d8ed947af26a8fda97d2a49437c0111fe89590455ea53748e9fc372781fc804
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-watcher@sha256:f0540b9c0924aa311caf8f044d1a9aa5a1925e0ef20ca028afa3875b7074263e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-watcher@sha256:b4e596be62c98cc51c3891906f98d57370784232f383cc1a696e040feb983cee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-watcher@sha256:51c1b55daa32bf3014d545bda97c7fa95ae1b0002ac9974ccb7144b2f562510f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-watcher@sha256:a610d8d8f82752b0dbe217c16110d2a5bfd4e3fea81d5f813170474d16073761
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-watcher@sha256:69f783c8f66e1c4a8f06a9fffe32160ccb30b712cb52ca6080f4546aa5c3488a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-watcher@sha256:a35bc66b4c6357ac0f25126ecfd0dd9bacf8fa4317c0bf3658a59d5e2a6e1665
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-watcher@sha256:ed23dfcad65e2c9931eabbcfe9d915f8d4fa08da1821e6aa6772130c2e3d0de3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-watcher@sha256:6006acb385f234f9e4b76444f41b894df3c04fb0b554016a60875602e4c9435e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-watcher@sha256:4a66fe6f7aca89e3ef5f6d10f9cdd95bd5d512497896c973243df991c8e2edf4