Sign inSign up
k8s-sidecar

dhi.io/k8s-sidecar

k8s-sidecar 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine-dev, 2-alpine3.23-dev, 2.11-alpine-dev, 2.11-alpine3.23-dev, 2.11.2-alpine-dev, 2.11.2-alpine3.23-dev

Index digest:

sha256:fff2a0123cc0b59fcba77f0dc3ca838dda34c4b10a3512c4b625997392b5890c

Manifest digest:

sha256:d4dc7187ab611b8cb98225366d0cabe2b692375e79aa56f31c0a7b82bfaca93c

Size

26.16 MB

Last pushed

2 days ago

Vulnerabilities

0
2
5
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8s-sidecar:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8s-sidecar:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8s-sidecar@sha256:b7c690d5103aa99a8cc907def607a5a83d4cce69d3e020ba421d3f30de02f4ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8s-sidecar@sha256:1f08201f4265051f6d5f8eb9dce51e502dfd0769b68c1e1256edbca075d77e5e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8s-sidecar@sha256:91c9f946e7ccb4fec7bdcbe6138a418dbcdaa7263a53691c55190537e3a2aa27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8s-sidecar@sha256:9910e4c5b2a1d96403bd71fc17883ac93fe4552483b0e9de87354405f6c22d02
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8s-sidecar@sha256:d9e4bbb39f8554fd46d2bbb632dfb0bbfe3d4d177cbdf6deac8e5cfdcffaa4dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8s-sidecar@sha256:020570439687bc52b6c0e3e0ba1f4927a8301c3a633fe163938a4accda2076cd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8s-sidecar@sha256:cfb79362a517079b7d1d334ef14fc12570a2da8e5e553a802103199f9303cc62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8s-sidecar@sha256:3d09f3209eea594c7034b952f2a73fb5adaec5a5a110d9246ee1a162765e0c1c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8s-sidecar@sha256:68e5b33eb30b393f2530b710e4d018814f18e60ca4506a47bd5ce69f1f939e73
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8s-sidecar@sha256:c30016fc78a46e6a2a7f8790c68b5ab1e133f7323c0a297834f1bff0a72de6bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8s-sidecar@sha256:3ae93ea0a8ff86ca6e83348a5dd244cbf09c37dbb908b18d6b77861f002d1783
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8s-sidecar@sha256:2ec8704504e5c090d3869f1ccb2056c74116953f283494ba6b6a4b07081c6df0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8s-sidecar@sha256:e52aebb34ce7d474e93131ee5f53e499cd37b001d61019e5b8b8f45e5ba1c172
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8s-sidecar@sha256:7db2611755f816f042e1590583d4aed6cc5ec3a746235f5b24eceb9ae3af8473
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8s-sidecar@sha256:eaaba51f7c4f218f2e3f3d277ee1aff435aebe11e4a57e2ef6bdcb0e11f3a918