Sign inSign up
KEDA

dhi.io/keda

KEDA 2.20.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.20-debian-dev, 2.20-debian13-dev, 2.20-dev, 2.20.2-debian-dev, 2.20.2-debian13-dev, 2.20.2-dev

Index digest:

sha256:7a4564d2384e328acc12e4e42ca682b5b4271fd08b936a13b1eb808cad4a8cb0

Manifest digest:

sha256:cfe42483a90846bb5ef11eac006fd72ea640bef62c7535ef9d3486d017b9c5e1

Size

102.29 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keda:2.20-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keda:2.20-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keda@sha256:2da18287d6163feacde91da0750ef1d1580dc593c22698b1507c0fa391de07fa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keda@sha256:517e0039ffb9128b4ff9fd72c59bf6ba6c49be8aefb5d9ba76b6fddd5ace99d7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keda@sha256:d306d49b7d293190f73434af579a47bf87d4903ec8121e606a2e4440ced97da0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keda@sha256:a3980e5ac8aa343ffc012f16a2dfb8a9fb23d69a35dfd1e36cc21f9900d1d75a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keda@sha256:7e6877b608855be350e6031b4cc88d963d97768c03f5e25b028a808e00f0cdb3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keda@sha256:e31087944c9d8aef33ec8eaa497ce4addf2b8a91ce6704d9c70deade6dcc21f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keda@sha256:1b6a5157cc310c1ea5bfb2c66457a6a48bafd47bec4a37e986f9b0fb13a3e558
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keda@sha256:4efe13d65a1686fdfe1dcb3e454b48a94feb15706cbe29c229b3b2a257e50ce9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keda@sha256:a6f363c50249a234c84a78aaff2b6f6d327f03d004a6d040407ad08e856f71c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keda@sha256:a157bc88534f5e2cf0aefc2a436938d87a79a1777a6f03c55b09ccf2c68f4521
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keda@sha256:79b7b8c93466bfff128df5466b3b71299816d6900dbddd23a66a8384baafd80e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keda@sha256:e933ebfb7a409f69b37b57952841b5f85276db3df8e52883294949e09cb656eb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keda@sha256:e8d9f77cef0d476b7e3ed9bec2fc6ae7690da1e1866d6dca5c6c0b207e7d3cc1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keda@sha256:2c9e45986ec2bcef9ab66572500914d790d3850afcbe7e0f627dd118c88332c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keda@sha256:55c760baf801e6382a6373a359cbfab6e37d31c041b7d41569a23578ec86d06b