dhi.io/keda
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.21-debian-fips-dev, 2.21-debian13-fips-dev, 2.21-fips-dev, 2.21.0-debian-fips-dev, 2.21.0-debian13-fips-dev, 2.21.0-fips-dev
sha256:e60b0974a370a16e38d9909361760b5f1a212a136564292a2fa1b7fd914fbc32
Manifest digest:sha256:ff04466cd99b0ffb23efc402e3c16e628cce4a8f48f9ded69f332866634e96a7
Size
108.96 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/keda:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/keda:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/keda@sha256:ba402b2e9d1c750636dd92274c6fa3651e13264e21d83fac7a8d2da3c43751aa |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/keda@sha256:0d27221d177bc9caf9c58cc90bfd4884548d2b4bdaf633501633e74a877863c3 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/keda@sha256:e7d98f3580006b60b2a7f78a60fe8e8958b5df66801c80a4231c48f7e9409dfe |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/keda@sha256:03fda2b81a56df7b006c626f2ca3ea60af82430fd931ba01ac89ebfbb21cd30c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/keda@sha256:a11fe7ba62c95cc8edad54e6ea6d446e654b8a2f3b55130a9b55b2bff54465e1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/keda@sha256:4b4e64e6b62612db8fcb8d5cb561d20154de75d00ba7e50cfb9f753ddd6c65a5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/keda@sha256:cf251c09ed091e13bafabf726a543fce9f1e251e2c997fac716b232d7e8128e9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/keda@sha256:a8bbdd2f4886e4d48739fdb8df6cdaf99a0beb8fd4e7bfdb3e944a7209bacfc2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/keda@sha256:c3cab16c98e25ef5bb474c44b6c14b4bcd67c99ba3fd2a386d3c411933708a9a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/keda@sha256:16aa60045e676312aeb5ea45d70e8ddcb0e5a184dc790e746017c32bd501fed6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/keda@sha256:64cbd5877a9a90e0f623c22326df4aa369634021499d87f293d3ccbb6e4598df |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/keda@sha256:3fbcef1ce2579db48e24528c1b48db51fd04cddc9e4cc888dc6e468e6d082a93 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/keda@sha256:8cd40a69f70699edb7266f4dd1e714c769f927af2d7f4e5d5d8fe86e5591c362 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/keda@sha256:4e03a8c7bb5d417268ade0e1fa5e59410056a322cabcab2e0862b86eebe62997 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/keda@sha256:32495ead512dbbbe7edbf9ce1367b885874355ca3f9060af79b395eb633bb92a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/keda@sha256:6fd31ad3655b87eae297c681924d4b2f1408dfd8e519e89c9f82069b85cb8762 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/keda@sha256:1a4615a5ea3594aafef00c2c26db6be2057731934e190d40bae854a7e4317da4 |