Sign inSign up
Headlamp

dhi.io/headlamp

Headlamp 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.45-alpine-fips-dev, 0.45-alpine3.24-fips-dev, 0.45.0-alpine-fips-dev, 0.45.0-alpine3.24-fips-dev

Index digest:

sha256:dd6e26b48ea4065a85394904d2359f2a465fe8e62d04f2bbb58c58cf0688ff25

Manifest digest:

sha256:aa2ec41caddfc8928cfb6f7e71a90495e2945f03a4114f3c5460f46e0545f1d0

Size

34.40 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/headlamp:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/headlamp:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/headlamp@sha256:43ab7a66ba6dbdccb91e361e1792d0aec9afe071bd6ac5d65ee6db4e33604f39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/headlamp@sha256:7d37a7c8f949c860f1798ad715d3666d13a81d5cb57f7b29e529436736e96dc1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/headlamp@sha256:f9b684f100482a76cd6a31c3caf36c477d0317eda91b13af71517521cdd7d551
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/headlamp@sha256:a7d2cdd87abba903df51f0b399c9f6f9be4a9444f4bf17fb159337e15c37a4e1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/headlamp@sha256:1fc399c2fb56ab923b5e1e6780b43fcdc43c4de4b498bdfd33bd41636a82ff15
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/headlamp@sha256:3d70fabb68294912b43b8bcdca146b9440af9a567ca74793228216d157046147
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/headlamp@sha256:86655b1acd75349943aac73a24f88665cba174aa772d7e4380a9701a0d1f42f1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/headlamp@sha256:ca752dbe7c9ef34a99d8567c7c483ee913d8122f6834626ef6b29c6f2d4089ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/headlamp@sha256:1b76268dde9bd22825dc6511fce622bbd101d0dd4d6255c77e9b46fb29d85510
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/headlamp@sha256:cdff64229549f07f731ea90edc36fb3b98041c64eac3fc8bdd9e466e2da45a52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/headlamp@sha256:17f13c5a741d1ccc809dfdb1d5b58d5d44ed5c83e83ee95cc80d875a2d02e93f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/headlamp@sha256:b63b3c23e4086b072053f112ccb6c57178e8d251b620e4a67cab541d6d9ebf06
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/headlamp@sha256:5985f7d19bc864859166db5f0b7a77d195076515b45ddbd8f43deb898fb00811
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/headlamp@sha256:91b30e3bd9b8b964d0ccb8cb85f972a742abcba83f98da6f88f921f8cc86ea70
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/headlamp@sha256:ee0a427e16b8f5d5a6d9544e1630811ad7fca0698fcfb0f1bd90223e34ee4918
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/headlamp@sha256:b2f1c607adf1064b5ccca487f472e46a36082227e4c704c6a513c1dd0341ddc2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/headlamp@sha256:d1f326d8e1b14d940cfda1921fefffa3b922a6bf8fcf93644177998f77c5ef05