dhi.io/knative-webhook
1.22-debian-fips-dev, 1.22-debian13-fips-dev, 1.22-fips-dev, 1.22.1-debian-fips-dev, 1.22.1-debian13-fips-dev, 1.22.1-fips-dev
sha256:ce46d07d0806f4c19c8df60ed90011186236937332d18775737cc1bbb00ccd14
Manifest digest:sha256:6c593ca580c0de8cd06a6e71e39f67431e83e675a549399517cc18e05ee21855
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/knative-webhook:1.22-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/knative-webhook:1.22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/knative-webhook@sha256:ea9044796db4518a6a86d85739b3bea53208ca2e9a7451cb6ba6b2502744b5a3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/knative-webhook@sha256:cd4933a5a53ecfc5f10c69eb7f326375cb6d4613b85c2a27c9e28bc95cd1303c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/knative-webhook@sha256:fb75ad465fed2df4cc06d8d03bcc85e0596c9d49c0dc3e1e7c4f3ed3a9bb9347 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/knative-webhook@sha256:368ea1e24637b25516d72f1e924331ade0b1f79124857a87888d23032d34857a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/knative-webhook@sha256:4d35b89530f823fdc8a820894a03b490d361dc86fdf5b8030071c8b5cd383d81 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/knative-webhook@sha256:21e80417ee17fbc70126564bcb35f423c0bd8f34852d15031a3abff496815cae |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/knative-webhook@sha256:e609595049f90cac12afd2e25dffe56f7eb2a95b1b11b1606f8c07d55f40ccc7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/knative-webhook@sha256:b4e7e6578274c7e46dd3a861f190027eabcfb75af0c5b761d99a2fb06411d6ee |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/knative-webhook@sha256:d3ca560b1724e55aba2d35971a0b19e83b8478d72022833487f7d6af6b43c831 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/knative-webhook@sha256:6afd0430d4d920191fc992eaa557dd66564e75479be5164ab3f1e3e2d9141df0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/knative-webhook@sha256:47cb5c1285919b61a1e0cab9734fa4febdf653aade1eef94e634289d2c1fa35b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/knative-webhook@sha256:f19365d906765f1425d404593d619bac483d2c8552711a737e3139aee0a18839 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/knative-webhook@sha256:25b7edd2e22414dc0cf2be52310e1480ad779097654beab34ba25c8841fe083d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/knative-webhook@sha256:c125de42bd0c3c93af5713a10d9742971bb0cd8331c886752f1dc76ce1905218 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/knative-webhook@sha256:fda8b1b5c330f652d3a79dc62f512306e66d9f7d19b39c135a28ca63a2a6c65a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/knative-webhook@sha256:51dc719bde344bd15c8de8391f057e940d93b768683719e32e8724f8bc867813 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/knative-webhook@sha256:60cc371ec515e25a214da12d65f59ad9487c477f89420e8f1d6cabc2cc7cb865 |