Sign inSign up
Headlamp

dhi.io/headlamp

Headlamp 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.45-debian-dev, 0.45-debian13-dev, 0.45-dev, 0.45.0-debian-dev, 0.45.0-debian13-dev, 0.45.0-dev

Index digest:

sha256:1fa36ebc76f20caee78974df8b6383c2f14f3d870f9e73b619537d71adba19f2

Manifest digest:

sha256:010923da529e518fbfee08c65a288fe451b517a5b526e64705f63e26477e9c56

Size

51.55 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/headlamp:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/headlamp:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/headlamp@sha256:27134d3a7f90b18b57690f51878b17fa75c66438a20f5aa3ae92cb3e96626ef7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/headlamp@sha256:f3c50bc4f5bb70621ded661b96d0cb51333691634aa1d7f0e3a65ea877331c04
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/headlamp@sha256:7750bcc21d1310d88c6106834700ed609e250e4bdd5b93b978de59073582b70f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/headlamp@sha256:ea4c29cfcf611453154adb95851fee3ac5fbd0d72a3a44b7e93f3c18acfbc741
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/headlamp@sha256:f625ce2046cd4d6938f6fb3db42beab576c2fdbf63d597d4394bdc2483af65d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/headlamp@sha256:3ab2cdbea36fee7fd278932e45f9606fce757210e9f16d1018260d00f2eb9ef0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/headlamp@sha256:381bea957dee1a4b9df4a38c4924fdaa5b776800c27118a6fe914c245fe523a2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/headlamp@sha256:dd0d24efa00260267ff4084ba5754583d5e2e1ef371dfed35de7ba00db877e6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/headlamp@sha256:f69754965d128c36760f812d1c39109e6ed904bde1ac2fa3e895c9d5b04f2f5c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/headlamp@sha256:0e91af6adb5f7b8c82a45fd8b83b83a8d75a4767f5d57f1a5fbfec1c6b7710f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/headlamp@sha256:3247c0e5f2de87503edf04081b6d06513f30deea40707171d9f756f13cf28045
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/headlamp@sha256:4619d92f9a83b99043614260f7db36594cf0400d17f3e20bb4e3da767108f6ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/headlamp@sha256:98de47e8c8546cbfad6c72ae193175b6e7ddf020980063fca72ef05673d8474d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/headlamp@sha256:9f02ed4830c425be56f1788c3084ae81145e258cc80b204d8387993216c3fd81
SPDX SBOMhttps://spdx.dev/Documentdhi.io/headlamp@sha256:a72e11b5c262b98d5e1d9279a773e154485ba00dcbcb8e06fc7a748df8d828d8