Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.23.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.23-alpine-fips, 1.23-alpine3.24-fips, 1.23.0-alpine-fips, 1.23.0-alpine3.24-fips

Index digest:

sha256:225902a1ceda7af98c658325520516e5e412e7cd3d98ddab7280fc55d7de329b

Manifest digest:

sha256:721b416a7dffa0f082bc3b7af0811d5b96c3428236ebc943c2e101b16617b280

Size

17.89 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:1dc047ec47f84699dfd30281c6d806c8b3695310289b107ce129347e4bb658cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:609bb5d934c38b3a2cf7604edbd8967869c7fdf05a7f37085b890f3fef53afd9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:e3806b8b6bbbed9cd5dabd20cc9d39aafc451e0a464a5ed1f4bd7f4173a87b04
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:063dbb9d8c1e382b6af7fd33849a045c120f3abb3c6f8a5ae3f98543b1f22d39
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:1c2fcf95a8f45f0abbf846d5b2385d7970f055815f1d9ef37a30173c12502a95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:f3f1cabd84951da3a5a18912bf7b651518e87aeea10f9a4766c39c3cbe38f868
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:fac03aee837a5bb200717e37f2001be4e6b328811195ba72085c554c630bf546
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:2c0d2cd10f719acfcd0f7f05df2c38170bfd5c0eafe91e83e6a01e65bd88be89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:a443421a0099c052698e0b1841009b629145dc6b5379de02af31a133bb98d63d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:3d527d9f54b581ccb7d2af1d2fc8adc2479826a5f094a348e3bd7662ed79847f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:d7062977b0e16e0527d541bccf51e767d7126b637f936a0a616db7b1a494b3ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:b5ec5daae98ffadbc1da7a806d009ddfc3af90ae5eff44763792b8ac6d7c12ec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:0f31550d8df7f950cdfba44cbdb3da24d7994c9852e9efeeb237b620a13d614c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:30d508b57dcf50a2ad2e83a6db9dfb4abe80d8885232838ca554bd0ed1cfcde6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:204ea443e2e9957c3499631bf28acc6df8fd0dd0a35bca64b45a69e50d268191
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:894575b9d88b9d2bb6d14914d54c6b94ef5b208c437033b5e72327625446d7a6