dhi.io/hubble-proto
1.19-debian-dev, 1.19-debian13-dev, 1.19-dev, 1.19.8-debian-dev, 1.19.8-debian13-dev, 1.19.8-dev
sha256:1c10af1526e0e2ce46ecab9f7050f30c3b92558c7c7a6278c499d9c642e22e45
Manifest digest:sha256:dd7f821d8d2d7329a9df00875b4fd97ab1c70379c254392182bd0363cc889017
Size
38.41 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/hubble-proto:1.19-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/hubble-proto:1.19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/hubble-proto@sha256:459693dd93388cbe88090305208eefea8747b9fc995cafea7706ddb46a9fbfb0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/hubble-proto@sha256:f246290c5630d880386412995b479e95afd62f2efa7dd53073cc61a22d388523 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/hubble-proto@sha256:fc1f3d217e9b8d6b97ef78644b72d376f69cdf189dd2465ea6979df9e1f00881 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/hubble-proto@sha256:1224f0351704d7a6faf361188760d64f5d855b5ed383762093959b191892d987 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/hubble-proto@sha256:15bb6c7ddf84ae558a56fc21a9fd1d4fd2d4f38db8c00d324885534594973dc0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/hubble-proto@sha256:d658998d61ee77c0a43af79ed105b52aa4653bfa4ec0719390eb091ee57c6f03 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/hubble-proto@sha256:20a72ff4785bb496568ad6e0c1839eaad7f70eda923d674cc60e40ae96857fdd |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/hubble-proto@sha256:d2897e39cb9d4e9cc47f9bd6d702761026c48cd5360a2ccbab15921ae98dfbb8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/hubble-proto@sha256:fe65b6c378ef7580618d148df34ed87865627da5153af62e1e4a603579649077 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/hubble-proto@sha256:da9473f8a0a12d0351a42d6beb042bc9858957fb66f251534e9b94406b04f522 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/hubble-proto@sha256:8b4678453bef3c2e8ee45854e1f4d1f40c136c686dc2df02dd8c22b72463a4f5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/hubble-proto@sha256:2ac2cab9c958e58c9697f5f149f220077def9b150141b55fca57e69af541e237 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/hubble-proto@sha256:9815c06b9b9495616fb1d766c546f176f6d56d42eb5e968bba599702854f653b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/hubble-proto@sha256:d952b4944afaac2984326c8d28ddb836539977011afdadb56087149f1d5f5861 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/hubble-proto@sha256:757f3a1b77d1254ba365dc28ad488dec565007ea9f6d753f8c317cbea2b2869e |