Sign inSign up
Kustomize

dhi.io/kustomize

Kustomize 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.2-debian-fips-dev, 5.8.2-debian13-fips-dev, 5.8.2-fips-dev

Index digest:

sha256:458928ab403fa0776c5a788e5dd6d08a9078fcc96c155ed7fb92780ecf184738

Manifest digest:

sha256:4ccb5fad0b111ba85375684cf4f16ac7c6d4354e105f86faf6dc2de4f0257357

Size

49.35 MB

Last pushed

3 hours ago

Vulnerabilities

4
12
0
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kustomize:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kustomize:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kustomize@sha256:40fc0bb9806a63bdc67c55752f272ee123af155812cf88594ea8c7828d66ad09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kustomize@sha256:2f5dda689deaeea298351c2f445bef9173bc9848e5058e6e913288d91b1137dd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kustomize@sha256:6e2bfafedd6ccc8f8f7aeb86e182784d33ce862fdf77eb1febe9ef882775e968
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kustomize@sha256:9739c5e4884237403efe4a180140d66ccd7caf7814a3e7a295eff93d223f3973
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kustomize@sha256:ed47f0c56ec185ff86b9edd2d26c347d6607ad35e8e58892379025f40df6554d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kustomize@sha256:bb2b7da39d253253a7d050a2bd85c7d40d55f0151fe394327af1145d9401a533
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kustomize@sha256:ab3622d53f3f097ce71e417e5f4a2688b96f433f2e755fe3b897f162930b1a2d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kustomize@sha256:a3196ff1bd0dfb7d687ca184cb9ff007d2c509ee010b81e6c0665c4d83cff45f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kustomize@sha256:52d5d4b3a09d49b1d4dce666cdb61349af097cb14ab4e31cf6e99cf31e068821
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kustomize@sha256:3a45d9c7e7296c8a948a2ab8b4f5f43fa68fb4839872b78a066797570fb5ea9e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kustomize@sha256:17993c551b07dbba7bcd96a140893b6187e8bf864c841dec442b551f6b370b50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kustomize@sha256:c05ccedf3b6d07c3b0e47feb2fc4d5725cebe42c671241988cf729e4d021bb60
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kustomize@sha256:14b8b3b8247f889ec5b362da803da353a8226e100dd89ff086d4191797ee9da9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kustomize@sha256:247d494e4ac3f93312865ce684df2f4fbb9b614d8cf9534cdd44f1bd6d171096
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kustomize@sha256:8c88f667740ca8b37b41ad3738f699c1f3d3fb319ccd95654a81affc47973516
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kustomize@sha256:ef5aadc0d92d96cf12dfd07af335912c28e8481fa8254e0120a60002516768c7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kustomize@sha256:36097157f22bf530b72462d13930292671901c0227b7ca29c5bc0f1c2e48ef35