Sign inSign up
Headlamp

dhi.io/headlamp

Headlamp 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.45-alpine-fips-dev, 0.45-alpine3.24-fips-dev, 0.45.0-alpine-fips-dev, 0.45.0-alpine3.24-fips-dev

Index digest:

sha256:7aebe0393ebc16a26761423af8a389e239f4dddad99957eaf6db44f9d7f5fd64

Manifest digest:

sha256:fe96f66bb1f8b8412f25de46c9be42f652c1393e07ed79147c4fc47cfb5f1548

Size

34.38 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/headlamp:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/headlamp:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/headlamp@sha256:78dec24616075e872d4d472c8907a8f4b5837f49c8fe5872bc115f95cab9b9bf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/headlamp@sha256:73459ab7b6ebaef98c2de6e3e6c1d182eeda3b4a95c961a20eb7ebe0b382b267
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/headlamp@sha256:f55c6704fc86c4c21e15e7dc697c8680f25b6c08d12b501873eab53bec40a291
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/headlamp@sha256:a5c7c0adb0c4531c00261509abd0eecfbad9466dc9b064dfa0273af0851ea0e8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/headlamp@sha256:421af65287f5385baff84a21a5d88b4dfbcc9b3c1551b424be91fdee413fccd5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/headlamp@sha256:89b4fee4e9a000d6987a644f093460ab6e6f7f0efe83439e340042458d07d0e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/headlamp@sha256:63bf620d3479efe1ae43ca06ef743478d4613c3bd8af6c611dacfb01e5fdee78
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/headlamp@sha256:84a7345d459f436acef12dbb2dac2759d925d9a9e8ce6dbe52093e09273d32e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/headlamp@sha256:fca730b8ed2044ead171ef9251d9e307feef2dea3b822e524fb8b4869d477294
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/headlamp@sha256:28087869d2bc8de0f105eec4f96f18a7a611763e2bfa4093948796a36a75a458
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/headlamp@sha256:e18cbe5af8ca8f4ab3dfdada5c102eb27820397e039ef4958e788e0c5bd9d75c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/headlamp@sha256:295863ee2cf0cd6af952da6a175c760d53784f042ddc4747855c2f9b7158d773
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/headlamp@sha256:dea2079e164ed032ded23279f126c10637adfb6770e00dfe33818ddac55d79e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/headlamp@sha256:43889d5a742c960b0b0d231045e58ad740fffa22f28269fede5ccf3b83c2cdd3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/headlamp@sha256:4aa98c46500522ee2a4230f12ed13c58fab98bfe0e95da2d309c8292efcc19a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/headlamp@sha256:950323445366250d0bb30f148f7ba0631273473b305ec517b4a9b93893ef6f2b