dhi.io/helm
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.22-debian-fips-dev, 3.22-debian13-fips-dev, 3.22-fips-dev, 3.22.0-debian-fips-dev, 3.22.0-debian13-fips-dev, 3.22.0-fips-dev
sha256:70e7c1c2c5084c135777d58c4198e21a7d1772d5c3f1a94389699923eb1958dd
Manifest digest:sha256:a5237b952e9f8a31163daf067418cc07e79b8fee9da3e83a32b9b03adb69371f
Size
60.16 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/helm:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/helm:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/helm@sha256:a6cc8141b2b5dc418544064415a1587613ab33b04720ac01573ef0709d9a1f4f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/helm@sha256:20392198c965eef89ac0ec2212708ae7b197de06fdc57c03436149e708b3ae19 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/helm@sha256:39a115e050a4d9d2db82d9327b6899c3debe5c85895dc439e9e50c22d5d29fd6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/helm@sha256:97abd112c440b8a784d043482a860280a1a0fae96d161036244ab97c6863f32d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/helm@sha256:06844e3b60d12b3921913a9b5e55197c589e2f107f00c4d0ef3a235c6ae978e8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/helm@sha256:32fa4b4232a251b7c7320ac58c1b07ee5bd43fe17a7a981acf3f1a5f7b325ab9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/helm@sha256:055025c534c941d22ab949307846cd23fb3fb0f941688fe12874bb025a73c5cc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/helm@sha256:ef32a8786fed95e8753e92e4b13674749aa31bd47b488f8ad18ea94262d64450 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/helm@sha256:352fece0d4faa4a672f90b64e5a65d2c04aea241c84cb247dac047f9e6b6954b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/helm@sha256:9376501797c9f805863f574394812a6ce557d64652f4c61bb85954b09977c9c8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/helm@sha256:668f8dc95276c5fc4b59c7b3b4dc1f1c3021e75389927dcf201beebb228840cf |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/helm@sha256:6af54c3e9e21fa2638cad8ed1166f94e8dfa7e0eb6f2a16a7a7372bd5149a237 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/helm@sha256:5bfa771c0efb8338955206c3a137a60b97b8ca8b2c5d2496cd8427a143dba8dd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/helm@sha256:2073bdf8331ae02059746bce842ebdded2b3bebd86124260f3f576941d54ff1b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/helm@sha256:573e0991b581ca4cc0fbfd814afc5a96e2b234c598f0501ec1f8b11feca27281 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/helm@sha256:3c34e99f84f015eca9618d9d6ea58f3b348ec22f754de393537321f31af74dc3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/helm@sha256:b24efee04a78dee47c6b369aae88bb7fc5f256986bb3490f168bad283bfbd384 |