Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.23.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.23-alpine-dev, 1.23-alpine3.24-dev, 1.23.0-alpine-dev, 1.23.0-alpine3.24-dev

Index digest:

sha256:21dd6d1408291e6b6b190e86ca5d6242190b812ab97f4600b98a6ec652f6c06e

Manifest digest:

sha256:155cf55e0ac21390f1db54e29ac70a0189b1966f54f2cbe7ec6a74790d0044ed

Size

33.42 MB

Last pushed

8 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:bba5f2299b8c8fd09a421eadc5034e54d867d5cd92eeaa3c3a677eda97d3a53e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:686826b3c050b2d285e259d563ae7e3808688fedf986f0f6ad306712f5856c4f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:2c4a55f54ed5278143fe11c610519a66c1288b4ae0cb513ce8989a6bd21faf80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:52d70f2d8a3e029a20d3eb51e99b4c76408bae9fce8fc5465c58a97e32ef99b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:ad675c9a4c3adc9d762630a2a36fd6b16d3939119806793f2445e6e65db760fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:d60656fe97cfe1e22d967b96d2454cd787c823f6b9fae2ac18a5a977e4eab3b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:df4ed19122504ef0588377a58af8104ef1d18cca2c18024809710978abec347b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:b3074021674efe44b4eda6a817cca28825754642d1c1346bab263ab0703bd488
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:be8db4b1a4c62395900970290b04dda2ac4900587406fd1dd55dc774ab73f55d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:8dc175af67a154a0f0f0104a196c076e9f0876aff99daba04e26e7c647c5e319
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:cca3a243b5cd71b8fad8ac01c8ea705ead720c8d68d7f667ce0b55d423b66717
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:093580fa198b6c89ed9cd5624b1770126f274e2c8b131eb69fae4ec95fde8972
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:a2e7d0567d55c2e3015a708ee13811761c0ba4c3663f2fa1238cda7cfee3b327
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:a057c7b842ffeadda7e1dd3ffc1cd176362798814b6ee9dcd419f4c1fcd264bf