dhi.io/hubble-proto
1, 1-debian, 1-debian13, 1.20, 1.20-debian, 1.20-debian13, 1.20.2, 1.20.2-debian, 1.20.2-debian13
sha256:82c1742ed94570bbd291c0baa6d953b0f1fea50e35b683f8e8848f5f4c2567a4
Manifest digest:sha256:a948a791fdc8460f6b51d7725200eeaa6ed59268de960aae77eaa7a37518486d
Size
15.76 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/hubble-proto:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/hubble-proto:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/hubble-proto@sha256:167ba8d17da80d8c3c7dd5cd1e03c6d7800c9923ace226dfe194bb32f67472cc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/hubble-proto@sha256:8869b2e45e1d724fa0c0d93e73856c0606417feede819c9c470b45e71db8a950 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/hubble-proto@sha256:9b1b92e1c7133511755bf7f053a8ebb5d7a0c8aad95ee71d118987b590a6a745 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/hubble-proto@sha256:fea1b2e4468b20e6b667305d43b166560afc726f8d680c893679520284547072 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/hubble-proto@sha256:f69727dcea3373454ab128c87bcfcddaa7b131d5952347871deaff5dfe470ea9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/hubble-proto@sha256:5175e7f64eee3c670d809add6a98fdf733fdd27e9677c269e2d4a0fbba523812 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/hubble-proto@sha256:8b3a8f27cb830cc9da3aa5550897480859b3c70047f99c9eecf4c232ba2a7a44 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/hubble-proto@sha256:7eca7caecd43a2f859eed5e6bc240e37538a906d1c2cf966cbaefaa9f21b0649 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/hubble-proto@sha256:1eed01742108a1b5da66fd97734171801f38d78039eb1f98244f82ea373730d9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/hubble-proto@sha256:8cb8e6b420122802bc29d1a76832e904cb5dcaf5c1f1615d353988d6737a86dd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/hubble-proto@sha256:39ebf7db02e6b21bf5b5410a30ffbc10887b7f73c6eb467eea0de02c092064a2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/hubble-proto@sha256:c6d409d93f42241edc2d72bfa32b789549e67d99423055fdad60204ab24e7f29 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/hubble-proto@sha256:f3e8605c858695fabae58bee7ad4dffbada18316840f55e77d4cdcc0a74459fe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/hubble-proto@sha256:a17158055ba3543c1f11bc6765de8388c3f718f4b28ffa22c117499318dcc29f |