Sign inSign up
Headlamp

dhi.io/headlamp

Headlamp 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.45-debian-fips, 0.45-debian13-fips, 0.45-fips, 0.45.0-debian-fips, 0.45.0-debian13-fips, 0.45.0-fips

Index digest:

sha256:f99c4a094e90f85e1dd97551934d665aa577e8c553181187a0570cf5d3ae42c8

Manifest digest:

sha256:517d4854340b91dc11232d490107097f0a0dbe3b6c469a6bd34d795020dee67d

Size

37.08 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/headlamp:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/headlamp:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/headlamp@sha256:4e1dffec443410f0df472ecc8602de25d852ebedf3be1d77d25db2d29d2752f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/headlamp@sha256:685c25260c028236415302e28daaf7b2ab755556f10efe6bf6032f2a65bc5232
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/headlamp@sha256:0b29db6523452dfebd6b104f75fc65d1d18a4cd2bb885bb068abce6523527f8a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/headlamp@sha256:94166ca60860396c9a59a6269bcfc5a3c73b7391a8aa35ec5847373a360b2c76
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/headlamp@sha256:750891afd58c18c4e97eaf782dc1991c83cecee7f0888797695e54ad19d9a113
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/headlamp@sha256:c43bb2bedecadd373057028839116eedb9a7ccdfe5d5eb4e7b64e0d63c3a0853
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/headlamp@sha256:d7ba0cf64d503d5b2cea7e3a3a886704518dc9a113438bbeee18f2a6cb08ce0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/headlamp@sha256:b10ae0fb7e83c12dea821193e4596b2308ff7d8943abd3b41c56e945052a188c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/headlamp@sha256:1d60d1a24ab09209adb1c3abbb204c6a4723683fa28a5a0867fc2357de8519c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/headlamp@sha256:c3400faf85b09dfe888ade16a0d403a8973f0a6be9dcb21bd9aedf9665a0f656
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/headlamp@sha256:1a81bba40c213fc9d9b48b92bfb247e5bb52d69b38094438dc89d7d025cbedcf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/headlamp@sha256:7f449f8526bd94c7eed9a9ae0b833df33657de2efca9faf89e2c29f73b613067
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/headlamp@sha256:67b9447118bb915aa9ded5f8501bc6e807007d29836d43fad6e907d0de036899
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/headlamp@sha256:b19acca8c43f6418418c1aa781113ea68875e22c904ea83d5ac5fb98ca261a59
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/headlamp@sha256:5b294f4f229ff2688ff9879cd3d0d4466870a9d263f5e5869566f0c502fb03aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/headlamp@sha256:6905047f14fdd22824e1db5c8355a0a5560ba170e59217b29562c51811d56b23
SPDX SBOMhttps://spdx.dev/Documentdhi.io/headlamp@sha256:ed222c9428de27a384fddc9e27b3fc7b1cde39b8e4ee713ae443c5784e9c722f