Sign inSign up
Flyway

dhi.io/flyway

Flyway 12.11.x

CIS
linux/amd64
debian 13
Tags:

12.11, 12.11-debian, 12.11-debian13, 12.11.0, 12.11.0-debian, 12.11.0-debian13

Index digest:

sha256:12d16128be3b3179f304e5990721505c2803884c14c91a8d2aafdb7883da9e86

Manifest digest:

sha256:baf31163e47ff5d252fb98ccdece3d796d4b050f72ecad9ff732a254a742106d

Size

333.99 MB

Last pushed

2 hours ago

Vulnerabilities

0
5
7
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flyway:12.11

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flyway:12.11 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flyway@sha256:b599db31474644a1585ab959df7f109ef26ed25c564394b1e4d2064b75df9f44
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flyway@sha256:a3eb594a2294a165ecee081ea1be1e137427efbc7c3ec53753b33effeeba45e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flyway@sha256:5f6c546238c6db454071990c0f21031c610a16bafde1bae185a0b0d19de73555
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flyway@sha256:13da41c10e20d6e6b31f66d92f5d48c8a85282bfb558a674d1747fdef80fa21d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flyway@sha256:8b7c8776b1fe5940dc3e91a1987e3b23edd8c41eb2b19deebc909643b1acb224
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flyway@sha256:1dc3c683fac9546c83247de8775fb9018de2e4b794dc909fd128e84f4b0ba8c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flyway@sha256:9b1c472aa53f235fb5b8247cc727c4ac5c492a7dd2af76b38f3627ab1cc8b80b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flyway@sha256:38ca4eb3412ce876285874de943a1280be4f7df4f8b9448db33429a86a20a053
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flyway@sha256:b19c7051b273b574e9c7475a5be9fae608050eec951a52d75a833867c27d5175
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flyway@sha256:9cea967b5bd6e2b4b0576bec63d61a7640619996a4017dfc76be7b394cc11b63
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flyway@sha256:b08b2d5e148a205ad27e55fe6902611fc4dcdc0e06e016295a2c7bca7ecb5a18
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flyway@sha256:e20470e822cf7ce6ce2f2e80d7f29b5eba5cd54ac043e9355f08264eb781bee6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flyway@sha256:79e899ff40b783814abe8b64889b81fd687d06b783f06d08d73ec45ff8350800
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flyway@sha256:8a464f30365af7c7403928abab2f63bd51770a11da84ae48f01e434df240c1b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flyway@sha256:12af9fcbb899e97386ce509644590bc6fb8eb62a97969787ef303c225bf80ea4