Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.23.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.23-alpine-fips, 1.23-alpine3.24-fips, 1.23.0-alpine-fips, 1.23.0-alpine3.24-fips

Index digest:

sha256:4f24b453ddaf58e2b6d5dbc7628455114aed7c1af773154828e37b5af060aaed

Manifest digest:

sha256:a56fe7d177458ca18fcefd9d98b297181a2f88d2086fe0e3b461b93e7d490e65

Size

17.89 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:d22e66cddc7a7843b398347708c4baff2b1aeb89248b700b32a4337599302df4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:3bb4cb73cf0fec4df3dd6ddb369e0cdc17eafd21af4a0c82d0b2f14bcfd2f4a0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:e9c473511b7a7f6e0742447936059ba273c9aa33c7df1dd890a644ad21bba480
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:2b974453d07737266c79a42c6acf766abecd93d70e7fb2645bb2ba3e14e61bf7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:140542da4adff1af87889570d89fd0a6ad356c77892c29a49cbf11cc78d27be5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:2cd89b1852742572a08d6a057fdc4312bf5b4510ae336b8dc28ed022c24dbb85
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:2917313d8be0ec07b1242d7f926b2f8f6a8c7cf012c44011ba648881fe063835
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:a86cfcf33ee447d369e31e46e963267da3ccf335f1f436af57c87c937d60d1c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:0e9f789cd2d94c57acfe09629536a77b4aff2e14d6f3f1425ad4b85511af7d97
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:9cead2e5d934c167b530ab066ef0283100bfaa91fd0eeb69adefd5558f5740ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:f18c72ac8729a9dcbd49137efddce27458774fa0fe6c2f9387f54b9f8ed67c7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:ef4b3e1d4d6145f9fa8547b8389bdbb0145cceff6606715eea01dc25117ec60f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:766129cea27baa0a66d216c22bf22540ef163a1e6c8c626ff41a4d703dffe72b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:f037687bf0f991410c8a1f0c144e6125d33692bac40292724863c1b1b632bfd6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:c76b71fc13d6ec495b1c7e3355f887616d13afffa6f33297b4fab03267220725
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:2367bfac70246c951064dfa1c5094543be2bb3acb6cfa691341814684aed3bca