Sign inSign up
Helm

dhi.io/helm

Helm 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.3-debian-fips-dev, 4.3-debian13-fips-dev, 4.3-fips-dev, 4.3.0-debian-fips-dev, 4.3.0-debian13-fips-dev, 4.3.0-fips-dev

Index digest:

sha256:582603feeac872361b0954dd21566a00eb6510146e15a946bf63fe7ec393910c

Manifest digest:

sha256:b5727546c9cd877f52d3b890f4b62b46f40d941f3c326ba339940ef42880caf5

Size

63.22 MB

Last pushed

10 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:031b22df74083a1342f6ebc0d34825ef678368aa368bfd96db5d25973dfa34a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:e63939617fd76f0d3703aa956791cd7c383d0c4a5347b35be6f070a9e9b88051
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/helm@sha256:5e14b7c05aa20eb9f0789e1a551571ea42df4081ff84f23cf950f8fcd38d2dd4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:0ba2dca0668752d55cd11dcfacd73b338201be58c268f079f9261e713511d0cf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/helm@sha256:8c4160ad523cae782197ba791fb043bbe91650de75e113fe47275d90b4101a15
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:020eef51fd8cfcf9923aa0dc6513749249db689352fbccb0383618b80cc0ebc7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:7d2d030c6399f373c25fbfa52334daf5507f6c530823ca829d17667f01f9a915
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:97e9b3f0e71da8896f0d690caef6bb7884acc86426dc76ed491c293dfd9b888c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:e26d4b496f4dc115e10381c40d2566f3d85a1253fbbbd0ae1bf47ff082484325
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:358e2ef087485aad5dd730de8e2d54ee755b56496314838d070037c12b3fee0c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:52838dc85033422a269a84d6e569bfdf07ce4fdb1716344f984927056c7a5fec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:80d5fd955d08b7ea13f073bd69e06fe8af549402f95773f848eb85b788313596
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:bbb465c9685892c8d966b5809d6cd0624991125fdcc1d5e2680e1175d5005cc4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:38e689b85da5d24ade1d3096229ecd5115ed6159e50f6dd3b1c7abf823834076
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:f0852cc25c269ace93e234a3156d6f2c17abf16c52b508fc2e3fae04cbda995a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:eda83a12ed5d8a412a2b89e947a4ef7b22d55ac861f1ece5171df007a75a89ac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:decaca5847bdfba290f2b11847df4afa1851a95287415eec6c8cc262f13db7e1