Sign inSign up
K8ssandra Operator

dhi.io/k8ssandra-operator

k8ssandra-operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.2-debian-fips, 1.30.2-debian13-fips, 1.30.2-fips

Index digest:

sha256:2babd628b060382cca3b4f28181dad37334e8847fbd22a8a636c473380c0a3ab

Manifest digest:

sha256:34d74475ee13ce1e8e4d997093b17a25279e228d03cc47dffb21341b1f9a3120

Size

21.79 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8ssandra-operator:1.30-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8ssandra-operator:1.30-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8ssandra-operator@sha256:c23404a8532e12bb59a1c6be2466743b62bdf8246e51d9e19c599a7d0e9f03af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8ssandra-operator@sha256:47f3f26730dffc32a5f364ec094fbd3642b0be75b7aec573d3d29f06daf2e8ce
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8ssandra-operator@sha256:11e73a574647ef5721acc3fb0d98f7438a1f5b0a43b5e88c67836ba018daa3af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8ssandra-operator@sha256:14d004119a8bce503071d606f1560982aec7a304edc2bfa1a259336e51cd0eb2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8ssandra-operator@sha256:cdd374b00daaeae4fbf9bfff5eae2a4ab7883e22b8db8674b5fa1adf306daf46
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8ssandra-operator@sha256:1126a01be2a9503a255e0940482b67563cba2f5700563876f4db9a9c96df2b82
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8ssandra-operator@sha256:ba0956fdfa7335850f2d277e009c5c5656c41a9f071f2f8893dc9be4307d155c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8ssandra-operator@sha256:b27a25b20f9ca29e243d3cee2238899f21188b30ff6b119c5ef9d89a237cebe6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8ssandra-operator@sha256:1ce9e06a532f9f3f074c1e1924e1ef62fe43bd574a227266985913f522e2500b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8ssandra-operator@sha256:c48253a88af825b22a9744a4f2a19fc740c7fa0de66f2d0db864dae425ea3cd6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8ssandra-operator@sha256:0ecd7921fc20544c42c6509700d9f92c85340003501c1d062b8d882eb53fc49c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8ssandra-operator@sha256:f0a01be87824db12222ffa7f594c37987274592bbce6b53d717ed585dbb84795
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8ssandra-operator@sha256:3f96712a403c8df676607b9573a31b63106aaee1b18d929c8dd53ca3aed09e2f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8ssandra-operator@sha256:e6a46f49b70482e327974e1c3fe025c1c1e488d1d21a135bffd21d5c29c7c10b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8ssandra-operator@sha256:75d6103fa170aaf803770c092788423ba8c41bbb60b8375f38412b42b678e53f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8ssandra-operator@sha256:ab2a3a92a58bd9cd7d41edd5b3dc449ef6f280bd74fd6afb7c51b97eb89e555e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8ssandra-operator@sha256:1c13e93d00c19df1d610c01234471e32d77ce6962044b1a09f2dceb57132993b