Sign inSign up
k8s-sidecar

dhi.io/k8s-sidecar

k8s-sidecar 2.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine-fips, 2-alpine3.23-fips, 2.14-alpine-fips, 2.14-alpine3.23-fips, 2.14.1-alpine-fips, 2.14.1-alpine3.23-fips

Index digest:

sha256:a1c9ff44acc825b7c61b7edabff2a11b5ac00785a781467bc4d422219f4103c5

Manifest digest:

sha256:67dad554492a7399692f815a6b67be1ef2b95aa92f3b6d2eea3fe758d390bef0

Size

30.01 MB

Last pushed

4 hours ago

Vulnerabilities

0
2
3
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8s-sidecar:2-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8s-sidecar:2-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8s-sidecar@sha256:4ff99af4f2cca8c86ef4ec10169260de21eb33e66676061feadcda5d025b1bf6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8s-sidecar@sha256:2a27385518977612b1b178d0dbc292e2d7a7503c3e5c170bb5eb055e729e43e6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8s-sidecar@sha256:7374e033444f4b40264e6fc4be4e834330186db893b0881f386e51fccd2a885e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8s-sidecar@sha256:3acb54b87cc052d5b8ac6c6b325454eb707e8bedc93cf88535bb821fd8e7014c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8s-sidecar@sha256:4d86d38f8cfdbce839c13f7c3f38957ecc407bb3888ada4e558a0b7ba6cb5c22
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8s-sidecar@sha256:f7c490d42f926134126e614ba02ca5ef24953c9d1984e67607b68fbc8d4f57b0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8s-sidecar@sha256:6d49779d1a89b6b81a76454b195fc5158992b926db9f4fd7c6b0fad7a58b17b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8s-sidecar@sha256:a794effb03302ff37638c86e5f8d9a4bd8b2d7a491a2d618a8b39f2210673eed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8s-sidecar@sha256:dda9637f037785dd826842f2c3f0ca16511691372faacb18a852e948b109dd13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8s-sidecar@sha256:77f16997afd3da2b29ee13227841597e8694b8bc24b12b19891e9342832a4c00
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8s-sidecar@sha256:b4f72f0966aaf8aa3e6c3407a8a3bdf12753eb569749f5d0e5cb56974f0d5db9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8s-sidecar@sha256:304d162948956c7a57daa64b495a197d14637f662eae3a7c44e7903d65c8f8ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8s-sidecar@sha256:3cc69aa87a32765510a20b097d868367f077c39da506ded956cc3c61cdabe018
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8s-sidecar@sha256:f8972afc8e1124073903b121b1f2ccf4b06442fb9033823170217e5ff896ffb6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8s-sidecar@sha256:c37f5229c2f09d04e72e336e13bc3fc4e02f78242dab073f1ece5cca5fa0028c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8s-sidecar@sha256:3f154789b50310fd0f07c247a5c9f1941cd2f6dd9bf71843101c7f6e00da4836
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8s-sidecar@sha256:aea31c0c031f557c075034666e73723be3b2bf6290a43f4eaf4e1f0b529b7338