dhi.io/gitleaks
8-debian-fips, 8-debian13-fips, 8-fips, 8.30-debian-fips, 8.30-debian13-fips, 8.30-fips, 8.30.1-debian-fips, 8.30.1-debian13-fips, 8.30.1-fips
sha256:bc7a7485cdf23b7c08dff4dd63852e1f51d8df826202f364ead73b4544279a5c
Manifest digest:sha256:394553e8e5ef87d7ec74cb6e0a2fcba2987c4e662d3bdc5bea9933d59bdddb43
Size
42.63 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitleaks:8-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitleaks:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitleaks@sha256:6ea01409ef7801ab3970f7339c639a43a294f633dea5167c8444fc25eab40037 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitleaks@sha256:4528a8fc64d217af930125d52b106f6c65ba9e9a5def9c2a52a9dfe089104a32 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitleaks@sha256:b690427f0bb4373cb17dfe205f6442f46f3929c8ffee2e309907cd4d33abd2ce |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitleaks@sha256:8b79a178ae5e13aaa6dae0076860f92bac8503570ba5939eb21bb33e800afb93 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitleaks@sha256:54565896c0510d0bfeda0956837b0dd360cba3a3e73f5c1fc976bf7d04390612 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitleaks@sha256:5e304cef42480b28b7489275700832f026a41d3ca3320a662c26bc2588f3f63d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitleaks@sha256:f4126bfd1f395e8e1e99ca0d315ad18a3710f62d44aafd744ad822f9d71d2103 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitleaks@sha256:bbbf69341373d89b00dc752052cd19e520dcd0f466da46aa546654f68fc6827e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitleaks@sha256:63707adad8efe8d193b4c75bc8650bbf946d05f2588efceefbb6076ac92ae77d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitleaks@sha256:90d6c1a0065edda5f0a57cacfbf031b20bed8463e6336effb3db0e1da8e621b8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitleaks@sha256:3652984475aacbf6bab18b280acac765f68f5e5405e875c3da6de4d7920c2404 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitleaks@sha256:e1c1291c15f16e841a43640353804692c278c7458576982e03d5a2aab7c7df85 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitleaks@sha256:81afad00c9251c5970f6faeea4b99031e08c4fc7a9a5d704eb1e985dc7c3559a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitleaks@sha256:a047654196f58353bcd6971b1489556e5147161b168c04504e1d01a700f8e9d1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitleaks@sha256:146d60c667df8120708fcea5e5da478c40d777c9e4265697116d80dd680d74b6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitleaks@sha256:40f7ad956f932ab3895fea0c72ef5e3b4a6d70ee7bea11a979aa4e7aa7a85760 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitleaks@sha256:7ecf543d97c214962ab08693bf45ec728e857fa013ac159bacf4222540d52cbe |