Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.23.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.23-alpine-fips-dev, 1.23-alpine3.24-fips-dev, 1.23.0-alpine-fips-dev, 1.23.0-alpine3.24-fips-dev

Index digest:

sha256:5fbeecbeb3de0a965b05509dc817452a499198d4ab04a2820a578b8dc22f6ae0

Manifest digest:

sha256:9122b48c67f76a2214bd2b398c2d3a8639fa5d2947cde2d9766c4747e81eb196

Size

34.25 MB

Last pushed

7 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:ddc8a0e208a96c89f331bf1a77d7cb5384236d07f5888c2b3fa4c946411b40f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:49b7d1db4748cdb807b08de635ba4bf3431b84b91d477a22fe82d91292b93212
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:62f7aa4d7e4d0480a5d2ee063669bfe0afc4e70dc78d8cd2e5d0805873610ee4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:a6335a9aa80844c86192a78e3170d64cd6fad3605d54abf7503dca57a7292d07
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:93c554121e6f7bc51a3f55adf0ae4db0ab6c00ba7295e733613efae5a1e4085a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:236aac6838f22ac50ae07df4cf8a85ce7727f7a11ef23731a070a11c294a40ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:750aa7a4afad9243efbc240e4ef46cfb424ef01ce2435d856fffa1693cf1499b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:0732426f0ec2821d8b2ed80237ed1e04d836e12319b8c19f0d63889d2532139a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:cbeed44497428784d1d6f3bc7adecee7a698596a7bf8fc1ae52bd3aa494c7172
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:7fe54db43aa0b1ecd3f6a79da5a6aee01e47227deda25a0a5406dac874551909
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:6027ca125b336c389b2b207a40d3f470459e1231593bf9b314107b21419aed43
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:0af181e2d3d4a18e4461e04aac71a4ab4495f9bc237fbe7458cdead5c183f112
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:7dd86d340b0ef161acade55b3dfaad9faa28081d570095309871131a493ef698
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:d7bc21fbef9d0e1cbdcb291b98112dba043a277ee3baff0431981e06d5417f5a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:4266e5226e712f4ae43c9aaa59fdf13a16cd864ba0fa10267c46ad84b4be1c0c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:ccd1492f5629a20b2411fe77a9d1b0318a0d449420573e8f926bf1e3bb93c086