Sign inSign up
K8ssandra Medusa

dhi.io/k8ssandra-medusa

k8ssandra-medusa 0.30.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.30-debian-fips, 0.30-debian13-fips, 0.30-fips, 0.30.1-debian-fips, 0.30.1-debian13-fips, 0.30.1-fips

Index digest:

sha256:1a936bfed8d9790d125313ba2a2096b0e797c0ca912bb388781e39b6d4bd3258

Manifest digest:

sha256:c1241b30dc9f83f33c6b0048aba5205c9738be616bc037d21ce5615de2aef0c9

Size

87.17 MB

Last pushed

9 days ago

Vulnerabilities

1
5
5
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8ssandra-medusa:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8ssandra-medusa:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8ssandra-medusa@sha256:299a7bd2b1e3410644905eafca229c1ecf01e223d70220399fc705fae955fcef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8ssandra-medusa@sha256:d0c626d9188b754472af75ce6a3d9c84e726075d43fbaa3f7968b3be71135759
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8ssandra-medusa@sha256:9ddbf838143e1e55c687f82e5101e4f8f0038f94582b608f5ca312dac029eb4b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8ssandra-medusa@sha256:14d5d59e63d8a7d28fd13bdbffbc1a24fd53424dd30ce4e075fa1a79a60c786c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8ssandra-medusa@sha256:fe189232fd1231cf2c3b91e71f129029a89ccc10223e8abcf002eff33ac8bbb4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8ssandra-medusa@sha256:bfbdb31e1bb298d5556846d19df22bfb307014663485c82d405fce21048a11a4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8ssandra-medusa@sha256:5d891bd8c444d70fcb673bf27eae53d364180d7c9eac1fea8b005c603cf38831
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8ssandra-medusa@sha256:46fb34dff883028ef3ae0bb1b515864717ed61405f61207d41d053a748edd751
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8ssandra-medusa@sha256:b470c9acae1f2a61347bdb0d8acb71e868fe41edd08db12263510c71bfba7bb3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8ssandra-medusa@sha256:4902f5d31fa1811ed8e654657e2f4337df2cc2d3e305395eb36000fe1031756a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8ssandra-medusa@sha256:248c8c9c0a7a92b077af24bf6088e268465d0b179e03e26b1717438509b2c69e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8ssandra-medusa@sha256:5d22dddeabb987ac27b64eb8d1a87a052cd58f8e3ef53086b637ae9606680ed8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8ssandra-medusa@sha256:61dbe37161da6f304a458511c0bb71f0f519a647235cb9c9188df3fb6ed9d416
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8ssandra-medusa@sha256:7729aef9e0a8f331db619e7e7b0e050ec3c6333c7d81fca9121c6ceda05e7380
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8ssandra-medusa@sha256:37a88d18268e94587d97302e189c5bb57a47cef95e2f4e5f466af46f77c82503
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8ssandra-medusa@sha256:561a7adb439474bb3dad909c08e835a764cb936a7b6cd70e34fc5495d949c82f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8ssandra-medusa@sha256:2881f1da9d8753b42cb73fa6b0b60561b817cb90d77a105a774a5e4224fcf821