Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.22-debian-fips-dev, 1.22-debian13-fips-dev, 1.22-fips-dev, 1.22.1-debian-fips-dev, 1.22.1-debian13-fips-dev, 1.22.1-fips-dev

Index digest:

sha256:5837afc8e839e0821426beff5fdebbed45d94c47e73e20003b07731b6fa0c4df

Manifest digest:

sha256:ec5e087b7ee555a174886c56b87a529346defbfd6ebdfd8609e83bdf05aa4725

Size

53.64 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1.22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1.22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:d1e8c2a8e5d1bfeaa282ac9ff88ba55f3c1bcf179028d700c938eb504d3f742c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:679a72dd49f8576b68cda6affda7a5fe105bb690c32639ae92874fcbfbe843b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:3d3f459f92d5a38b1ff2f8b1cc9c755c73925999623821d6ee23d8e01324e134
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:045e0bc6f773c3a19ef20a376751f9b981a46d61b7aafd2e9576d4ca261e8ba0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:c7b5b9ae2f02a250a361264540fd50332678c312401eae948a7616302547de68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:7ee5d6e4f27f5f4ce85083824ba2a8178630922a0fdbbda6a7602c97feb9e2e6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/knative-webhook@sha256:de0691b99880c2022e67910581155411361f19efc05935472d276387135fc49b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:4c357f461d9ab6d7be2b7fcff20a63840d260274ec8986215b843c5f9a271c7f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:5a66e1061b8287c6d03ecdf101de67ddc7a2a08d633c53a1090d9eb6b4d634b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:9960a38e448e907c8f93b5c03fbca9038bd55ac54125d662a08fb6f4366598d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:e13a05a7ad87235ef88bd086e75b958549d8f89736e755dfab63916e0bc9de1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:c08740070f442e064cb6ab1115bbcf21b6eb6f1e80b0eff3bb509714ac266368
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:4c23d4a41533cad53b4090abee3fdfeb8e4ba4812b24e759b3109e6a3673624a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:cc828eb682e3c0b1acaed7c9978ee23fe99aeb840f6bc3d03b1d2e2223d2135c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:f8b6a089fe6877e829189b750d87ab33775e85443558e80aa1ccd07e057fd127
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:e01f780a0c7816508a29e1f6a33503bd7c9fcc9287dc5bfd3951d789e67f0c22
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:81ce9391c6b45a609d15577b971ca789a9cd2b8082230989361bb714ea4a74e4