Sign inSign up
KEDA

dhi.io/keda

KEDA 2.21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.21-debian-fips-dev, 2.21-debian13-fips-dev, 2.21-fips-dev, 2.21.0-debian-fips-dev, 2.21.0-debian13-fips-dev, 2.21.0-fips-dev

Index digest:

sha256:e60b0974a370a16e38d9909361760b5f1a212a136564292a2fa1b7fd914fbc32

Manifest digest:

sha256:ff04466cd99b0ffb23efc402e3c16e628cce4a8f48f9ded69f332866634e96a7

Size

108.96 MB

Last pushed

4 days ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keda:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keda:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keda@sha256:ba402b2e9d1c750636dd92274c6fa3651e13264e21d83fac7a8d2da3c43751aa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keda@sha256:0d27221d177bc9caf9c58cc90bfd4884548d2b4bdaf633501633e74a877863c3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/keda@sha256:e7d98f3580006b60b2a7f78a60fe8e8958b5df66801c80a4231c48f7e9409dfe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keda@sha256:03fda2b81a56df7b006c626f2ca3ea60af82430fd931ba01ac89ebfbb21cd30c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/keda@sha256:a11fe7ba62c95cc8edad54e6ea6d446e654b8a2f3b55130a9b55b2bff54465e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keda@sha256:4b4e64e6b62612db8fcb8d5cb561d20154de75d00ba7e50cfb9f753ddd6c65a5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keda@sha256:cf251c09ed091e13bafabf726a543fce9f1e251e2c997fac716b232d7e8128e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keda@sha256:a8bbdd2f4886e4d48739fdb8df6cdaf99a0beb8fd4e7bfdb3e944a7209bacfc2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keda@sha256:c3cab16c98e25ef5bb474c44b6c14b4bcd67c99ba3fd2a386d3c411933708a9a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keda@sha256:16aa60045e676312aeb5ea45d70e8ddcb0e5a184dc790e746017c32bd501fed6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keda@sha256:64cbd5877a9a90e0f623c22326df4aa369634021499d87f293d3ccbb6e4598df
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keda@sha256:3fbcef1ce2579db48e24528c1b48db51fd04cddc9e4cc888dc6e468e6d082a93
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keda@sha256:8cd40a69f70699edb7266f4dd1e714c769f927af2d7f4e5d5d8fe86e5591c362
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keda@sha256:4e03a8c7bb5d417268ade0e1fa5e59410056a322cabcab2e0862b86eebe62997
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keda@sha256:32495ead512dbbbe7edbf9ce1367b885874355ca3f9060af79b395eb633bb92a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keda@sha256:6fd31ad3655b87eae297c681924d4b2f1408dfd8e519e89c9f82069b85cb8762
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keda@sha256:1a4615a5ea3594aafef00c2c26db6be2057731934e190d40bae854a7e4317da4