Sign inSign up
KEDA

dhi.io/keda

KEDA 2.20.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.20-debian-fips, 2.20-debian13-fips, 2.20-fips, 2.20.2-debian-fips, 2.20.2-debian13-fips, 2.20.2-fips

Index digest:

sha256:2d234641378565bc23d2f1fd3d5e1accbe528a7e56e5ecb1489df1d37803937d

Manifest digest:

sha256:d2c4cc1bb778aa0dbbfff3976aa7ca460895027297841e7d90c9382b9fdb5770

Size

48.48 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keda:2.20-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keda:2.20-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keda@sha256:f820b8a90a3577067d3b936b19a722e6899b563235cebbde2d21e263cef59932
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keda@sha256:6dbd06d52e721afee4c3fa2580ad85facb1fe25ed32735a62ac561ce026d47a3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/keda@sha256:7f62ae96536abb01a723b1e11eec027ae69178c14d0f2f4bfcaa24f6c16d655b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keda@sha256:129bb880a9f66d61229cbe8e5503a58295ad28d8b3d6bb8e6a1e9098797407df
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/keda@sha256:342b93370820d6f0873aa7cc0c52203432839e687f507e95b7663b718340ea6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keda@sha256:ac4ade947a89457c6b92113ea1f2534b545873c825dee882d98366c3a56fbf4d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keda@sha256:2612b081adaac0a1cafa91616333de288efeb580646917846a69a413b6672371
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keda@sha256:8df1a61b747a8719b7db8eb86ae21fbac9547e81d6d396124440c93d3bc4f7ff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keda@sha256:8085703b6970a13e5812697be5c48fc4747bf015905d60ef08238243605af791
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keda@sha256:f25a08296adc3c5f2418af5ca2b5b54c74818b6ea4f922b32d52b625a9e5fbcd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keda@sha256:c18618d6eb87a9053e6429249a79cd13a1ff92517f175fb54c15ae80b4ea2f94
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keda@sha256:04c8b2732ee577ef637097a9d7e2a813fbd2fc4c106721036d17da7786f0d492
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keda@sha256:3e9af04a79fd031268e0b48bb89f4516cdb8a4688c37d05eda29e01f840b09b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keda@sha256:fe7b33f432c8aebf0c4d61c468f7fd69141b668bbb2f9da72aea081adaed272e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keda@sha256:2cb9e88ffe890a17c27837674fc13da4e641a89287584879c3c3a6fa5516b154
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keda@sha256:d625f86bf7e236c3793c7f012d731f24df4f6bb6406d60e7ffa288cf6d696034
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keda@sha256:96eb7d923943170cc58c9b32d3289f34008462b425562e2859a72863d36b49e1