Sign inSign up
Knative Serving Controller

dhi.io/knative-controller

Knative Serving Controller 1.23.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.23-alpine, 1.23-alpine3.24, 1.23.0-alpine, 1.23.0-alpine3.24

Index digest:

sha256:2d70fc33e27d41603c65d070af76d149b30b4cc37462da11e2dcf0c48bcd62c7

Manifest digest:

sha256:ec6a93562322c1d87ed439271037d0f9a064ccb8d539eea4074025c2bbbbe162

Size

16.68 MB

Last pushed

8 days ago

Vulnerabilities

0
0
0
1
1

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-controller:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-controller:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-controller@sha256:dd9d8a44faedf6e7597e3be087e482a9e8f8f0713491d3c4634b50f0c9b281d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-controller@sha256:442e0a15aadd137d37af4140cc6736b124d4444f2644cc14e61f5bb4887737d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-controller@sha256:b0247b90c1f4e9a32d6de886a1dc4f5f563a52fac161cb113742a2ab374e02a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-controller@sha256:52b0fd186de88dc7777b7f43f14a717fd831f071b112ff3b04cf9f5d117812fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/knative-controller@sha256:c6167fa7d77987021c4f92bbe4b394ef28bd42919fce433bc6fb5ace44d3c5c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-controller@sha256:6088d86ebdaf280e43279b1ea64b09bfa6757315f73406c88d690f83ecb9d715
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-controller@sha256:06d0dc1d4b380b82fb9982613eebbfc3d5d1c1b1de57f5a89c682eacc11910ce
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-controller@sha256:a92cfacd5553c125e25f746b03c6f03c45a5fade0556929c41b88d160092e2d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-controller@sha256:29098995e43b331d7f7270045872f9ed72e94253c766d13246bc94d4fe5d19f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-controller@sha256:fe6ed5b032d55892fb2c733c3be0ef4f7541fdf23e73b3cfd98f8e8a88f6ef6c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-controller@sha256:d398f8962a6b427c7a676484e85821d062a7f5089e7af76e0608fcfa88c0940c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-controller@sha256:549f3c838468fa748a3d2f411d7b16818dd5e2265848408eb3093eab0bddfd9d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-controller@sha256:ddc8ef281c3fda2d7b8d0854428e7b4179064d53fa98488895f8db1936eef388
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-controller@sha256:f229a2cc579abc8ee6c0bc96bd7a95aacb0dda537dc77645852783bec21da054
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-controller@sha256:a618961afa76119587f71a53130f7512bbede2e027d94e62d236a244b8a25e3f