dhi.io/jenkins
2.584-debian-fips, 2.584-debian13-fips, 2.584-fips
sha256:89d18c65b5329acf680c33ff963ee6e3eb8d889a235f8d749b8985abb49e2725
Manifest digest:sha256:75621503b4a65029e960ecaaef2c42554e6df83e8270de72a4c0da7be2e74899
Size
141.97 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/jenkins:2.584-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/jenkins:2.584-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/jenkins@sha256:2e08d331afc73399acb9c86b0350a2d46fc60f6aa1416305283bdb6dfaf54cd8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/jenkins@sha256:6a8cc4bf9506bf64e76bb2ccce404728552ea81ca9102db7522ce3f67ab4ab34 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/jenkins@sha256:9acba912d62e80b4b9d354c4fcc3e8c93f1607b51fe2fc3e253262ad22a4f949 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/jenkins@sha256:f2ee59d6925778cd23a759754aad5e806442a3d00bae6910daf6ac500d515c99 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/jenkins@sha256:38e4d28235543295b7e5a002f67764c90d69d534f57169e2587f0fa3a1c609cf |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/jenkins@sha256:00df11fdf3f6a27c23cbb36580e9ba83f984ca2e3d948b8a5e65eeeb93a6c517 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/jenkins@sha256:31322b607194b4717b90b4fbe53195a922b65ca97f6a0d295b1f7d6b8d915145 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/jenkins@sha256:6ab2e23ddd9d4a074e724b9f3d892f972d053d1e8c0c84833a12d73df5d0f392 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/jenkins@sha256:bf72afea42348a1001d7fb5a5421c4bbeedcb7f0a0ba20ab67eb3292506613f9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/jenkins@sha256:1052f707eb3a11d9729b59afbfbcf169d2656ad0bf360896dababf33e230058b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/jenkins@sha256:927520a80c3391f9266a944620e0ce412690ce52fcd4ba410d6f66bb981cfd1e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/jenkins@sha256:7bbbeb8c6beebc97649a5020fa3ad254162d8ad96f6556c8405928bc97cf8ee0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/jenkins@sha256:070c58d5b45bff0f6ed19de802581b186db3b03dde1f694e7c18ef0425d26a1a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/jenkins@sha256:7d29604262afda1667357d770e84004cb1632cc67b44bf2a1db74ce64faee5f8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/jenkins@sha256:67ff52e318df0482948ac441243783926cb8030f4318de2dd39c0900ae65fb1a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/jenkins@sha256:b682b40bb0b611a7578e4362ee3554d09134e2a2a80e0493174a7ee547081638 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/jenkins@sha256:34e9b0ecdaebb43db0eecb444cb4b49829a41f6212c9ec6293e243dc23567720 |