Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.22.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.22-debian-dev, 1.22-debian13-dev, 1.22-dev, 1.22.1-debian-dev, 1.22.1-debian13-dev, 1.22.1-dev

Index digest:

sha256:4997fa99111bab7bb1292bc0e282a1289645c37924fcff1abc4b7db943c52099

Manifest digest:

sha256:ac6bf69828aa9ac74c86bee49859f957d3387f63b065058ef4f8440f9a4e9a76

Size

52.83 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1.22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1.22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:bf9ddb4ce96380be6b0b4519ab49b453c279cbcd79dae23bcb0205062f5bf652
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:1b49fc6f21f0e2316eddabe2883dcfbc202842ca24194ea22cf65abb0bd976d3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:b8668279af83ff9575fd5774e4729f154f434b911968af7b3a07b5c1641bc7fa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:36516fb678e4464d9728fcc828a2cfa027b798662818632322b91955181b719e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/knative-webhook@sha256:b0efff44c3ea06b2dca0666665505346590584f3b82dee100b8cd6e5f37400bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:b925fb15f40c2704c59c990c08de37405a50c4f57b2299386779447a55018dac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:2bd37b68f8249c2bba61b46398c6d2a696ac69144e888252cbbf1693a81c80f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:e5331f74aaaada684f65a8ca15fe7ce5c4328409e8128fb626d9fcb1bfbd5a2d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:8171f15efc50054e6ae47574218b692aae0512251e9efb238abc789a0535d694
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:300823fe8f5cdaa02986e2978f0d383a30f321693bd304ef56bfdb77b7ea1470
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:1680f5de5b2bbdcb4dc081fd280ca61f0dcc495b36e38aba4e3b9a1615bf2357
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:2af6f5dcf2320aba3904334666778ace526e33a69016eeebce97dfca165def8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:4dfbde28fa4a2ce84dc8cbc1f98c62e116e8eeb4cfd0d24e6fea0215b53b74c4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:97fd94bca7921759ae13e0cd65215cc3577f5e82381d546332251478b678e94e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:070e37ebfc60277430cc2cefcfcb5122c93a682281d2325497ddeec86ae32160