Sign inSign up
Helm

dhi.io/helm

Helm 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.22-debian-fips, 3.22-debian13-fips, 3.22-fips, 3.22.0-debian-fips, 3.22.0-debian13-fips, 3.22.0-fips

Index digest:

sha256:9ccbb2ff995e4339ab348393b92f88a32ba63862704c1507812670758f95acac

Manifest digest:

sha256:94953d6a4819128de67add4c4557d877eae70e1d9e04c22abba1d66f9455c2cd

Size

29.37 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:ec83a4cca8c4f0f03d1c859c502e12f3c4f313ba59441539da0ce9fc82b70588
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:4dda2669b2b108e8c3b5f0041a71251455b1c9bf68ee9d8af237589443560cba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/helm@sha256:a41dc6c48d0fe8de46615531d1d05c5f1cac6325e13768c180a4d8cb35f8e772
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:c1f2ecbce658158e8b2dc07f60de831ebf7941ae494015140bf1c4bfea854598
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/helm@sha256:b96a488713964e2971a75ea244981fea755a57744f86622e812e94e76470af02
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:4b64d47cc20d8fb4b1fd6675bba09dc3128aa3a96f0441662c92ab64cdd9610c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:0c76cee8ad0bb66a57ae4b724c3fa8a9f9abec51a90afaf8ccb7dcf6b1bf5414
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:5b48b125c174c993d07009908f84ecc655147b1d981373dd2b345b5186007631
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:e6ae49c151a3b8b7f034ae863b9e34539af988e60b46e2c0a6af45323a37b1fe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:4ec5dd40c492bd15150478366b9d3d51edefaa0602ed3856cd52bed2a9fbd391
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:8e8e2cf36ed374a9fe3d422edac284174b5e12015f3c90b9534c2ae387e81951
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:58a179d49b07b8d968d78e7691d8fb13d2b914c085a0604a69469541373cda28
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:30cbcaf9f4ad9ba02cbb90eb9bd001857efc706445b19e025fd41d8f3acbb84a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:0b5f3271d18b528cccc550df8c2ccbc55f3a596d854ee3930d8fad8acb5ffad9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:7926f5f82c8750595803435222b4fbd4c5228b5d85bb18779ce8e967e54c7a84
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:d336ea882924480034e53c9c814058b7011de2f07038ae0473d273d706b6d794
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:44a3a673278f64cc4d2d4e5b107256d11bc003541a30d8a0c613d48565d1b444