Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.23.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.23-alpine-dev, 1.23-alpine3.24-dev, 1.23.0-alpine-dev, 1.23.0-alpine3.24-dev

Index digest:

sha256:cde59fceb33688c2c9a119ce8a4846dba64eff11f60d0ecb1a036575e8aa4009

Manifest digest:

sha256:9cd69301b65b2aa2a1933eb2ef6bd758c4b289c157294a0e12c239d93a31c2e2

Size

33.42 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:554f538c8875bebbeb01b8ceecf71a358517bc7ca759c9de830e60de63b86c76
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:1499c209e1f598850b8ad0209e3d35fc1225a5e083e54d6760254aa3b0d8c0cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:161aec67324af1891b07568a2f35434a200b587f34b7e06aaec2748373d1ace3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:7525c38529ab8f942cfb4f9147f27cebd7d34579c72ef0a1a0f9a769b2798f72
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:8c63ece3dda4a7bcb552d5d00363d45d40fa9494e3db6e50fd95c7289f8308c8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:e8be00378471c13b4f70d1ca4c452926b03e18e7441fe28dfe9afa91acc48084
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:5f672b83d9cd3b2d05eed2c45c7ede3b16413d73f7c7fd8295bd0ddedf027dde
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:09f333579a4eb5d57d704244281ed0ba319ebb75a837865008125b98bfba72b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:066294491481ce13ecf42c2705970995bd8c8edebbe717058ed0bd6f1f52ca09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:7a84a46f7a06bf845d6d8d39baf8193887b86c52e6d48939ef0806469f899ab7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:a392069f5576d276f68ade045892c100c2216bacac85081da2e7886654b08c7b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:bbdea9325efcc0ea632a787201a5c86d15cb8ee76005169104e2c9a23c220a0a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:b40540919b8f893d02130170c105eacf08b75599a0229e39269e032be3b330fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:2dc8d19aa547021a691586b496a88743fecf662d5123c03c7ef61bea14b01c70