Sign inSign up
Headlamp

dhi.io/headlamp

Headlamp 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.45-debian-dev, 0.45-debian13-dev, 0.45-dev, 0.45.0-debian-dev, 0.45.0-debian13-dev, 0.45.0-dev

Index digest:

sha256:4b9b8a617fa68deabbec73a2d6fc4574569ea78b64238a79b2c016b23f70334d

Manifest digest:

sha256:fb45076ce8fbf9dde1a604b40821bf48de447b65717a5a67eb77d6e8998eb846

Size

51.53 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/headlamp:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/headlamp:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/headlamp@sha256:7429ebcad4598a4066170ffdd3be8d8a41a4fa090a79477f1eabd50c24ff7bca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/headlamp@sha256:fff398d0509a09f8d030e0c252575a2a4242d8a700080af9de093d1b480015bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/headlamp@sha256:4f044ec1413b17b669dd12d3c83f95ec68635e0970fcfb6ea12e43955cdaa551
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/headlamp@sha256:fbc32c4ae822d0f73857553117abf7b0b4bd4c247126561a8d2b824cd2ee9c52
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/headlamp@sha256:b01441fe35c233011151d9cffb33549659636dd929eb523d9c954005d602f2f6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/headlamp@sha256:63b2e1e64fe22fc806fd8e6fde83a5a7d47d109c54fbe233646d64e1aabdc30c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/headlamp@sha256:b2f722ecdd4383f6056c51b2b0cbc5d6ebc60354d997affa11945b2a515ff186
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/headlamp@sha256:e5285a59cad63420ed749b885437eafd66905537d42a6ea0c398b719e11eadc0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/headlamp@sha256:8dae71c6b8b88203062a6c3b1861d593c18262d4d41e58dd2b0719bd4a2fe1e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/headlamp@sha256:0e8727a1e448755d74fcf55c78b11fa78bf071c88bc430a57b8ea4ffd0d53949
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/headlamp@sha256:e6749094c7295b4a4747cfd14746f3dc04b8d94032f23920e6bb10dbdcc4b9ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/headlamp@sha256:53d978055033b109e8ca6ffda674a9591f356e7f3fa582934b4aaf788103c4b3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/headlamp@sha256:837af6c788c53e42249163be2097cca82e8e359467fdf1a19fe08f1a306bb387
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/headlamp@sha256:3119382ad7dbabb00267632dd32bf4674c50e03f54b4ca81ca04b35b744fc98b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/headlamp@sha256:84a479f2f6be1f99eac6df2e9c2b3a250e28dbd8d735f0b8edf2a1817817fec5