Sign inSign up
KEDA

dhi.io/keda

KEDA 2.20.x

CIS
linux/amd64
debian 13
Tags:

2.20, 2.20-debian, 2.20-debian13, 2.20.2, 2.20.2-debian, 2.20.2-debian13

Index digest:

sha256:e400cd5c9faab2f7e44ae78926477ca167594e07a6d6d178bc5e10d175edf68a

Manifest digest:

sha256:7510660954def6410e79ece55c9f1755c5f4779a53a513d86e7a178dcf92294d

Size

40.30 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keda:2.20

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keda:2.20 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keda@sha256:9e0d5d234627c09bc2cb0c026af714e591324ae972601c57216f8537f126e187
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keda@sha256:1edfbb8a52f3623b6f5a1a41557054cfe496f1dfff16cdbc3ec5c39f9105813c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keda@sha256:02a27d8596131a21f4e2f3f4d0ca5bfd5ec90aca3820676016a16ab93cdfa03d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keda@sha256:3eb988d27ec3a856bb3737e4f7b6169fb8ef23c3fa57860657873a0a59174b64
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keda@sha256:b8c2be898c02717d3ef8fbb22123f128d7955a2373e4f8790658c122af22c12b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keda@sha256:cb7baa5c05e9f78f38e15bd47fb613cc48b92d6d4247fa9c842d53e9afe064f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keda@sha256:14d72ceee7757ce9b339b84aafa95ced468fceb82667293a1034d92aa9815224
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keda@sha256:f0a8035f79f83c7cfc6745e0534d563c1a1416e6dc86af2f3f03c37df38ecdc1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keda@sha256:c913e408eec0d2734c75e626ad16ec36e1e93ab820084e86197f650593985858
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keda@sha256:ad81a0507c379dfa5456e8f4b9d99d25102aebe16ba2127a05b5fefc951ce4a2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keda@sha256:b1d3e7833d041bd7f493e89920f22d4202d10e58938b51d665145de96c528a18
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keda@sha256:04f15370be7bde873ed7be493f82031b1579e284c1a2dff4c7ab3f45e23724f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keda@sha256:94340f37ee741dcdb17117c806f811b5967c988277e34bfec8338adb74204178
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keda@sha256:72c85c26addb844557191658264656b0d22553ba62a623d5a033cc216e0fd606
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keda@sha256:6f1b6463d8f03fd8e9c49d0517200fb7fa59f1aa9fe23dee185f18e76d6b4318