dhi.io/kustomize
5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.2-debian-fips-dev, 5.8.2-debian13-fips-dev, 5.8.2-fips-dev
sha256:458928ab403fa0776c5a788e5dd6d08a9078fcc96c155ed7fb92780ecf184738
Manifest digest:sha256:4ccb5fad0b111ba85375684cf4f16ac7c6d4354e105f86faf6dc2de4f0257357
Size
49.35 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/kustomize:5-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/kustomize:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/kustomize@sha256:40fc0bb9806a63bdc67c55752f272ee123af155812cf88594ea8c7828d66ad09 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/kustomize@sha256:2f5dda689deaeea298351c2f445bef9173bc9848e5058e6e913288d91b1137dd |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/kustomize@sha256:6e2bfafedd6ccc8f8f7aeb86e182784d33ce862fdf77eb1febe9ef882775e968 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/kustomize@sha256:9739c5e4884237403efe4a180140d66ccd7caf7814a3e7a295eff93d223f3973 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/kustomize@sha256:ed47f0c56ec185ff86b9edd2d26c347d6607ad35e8e58892379025f40df6554d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/kustomize@sha256:bb2b7da39d253253a7d050a2bd85c7d40d55f0151fe394327af1145d9401a533 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/kustomize@sha256:ab3622d53f3f097ce71e417e5f4a2688b96f433f2e755fe3b897f162930b1a2d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/kustomize@sha256:a3196ff1bd0dfb7d687ca184cb9ff007d2c509ee010b81e6c0665c4d83cff45f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/kustomize@sha256:52d5d4b3a09d49b1d4dce666cdb61349af097cb14ab4e31cf6e99cf31e068821 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/kustomize@sha256:3a45d9c7e7296c8a948a2ab8b4f5f43fa68fb4839872b78a066797570fb5ea9e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/kustomize@sha256:17993c551b07dbba7bcd96a140893b6187e8bf864c841dec442b551f6b370b50 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/kustomize@sha256:c05ccedf3b6d07c3b0e47feb2fc4d5725cebe42c671241988cf729e4d021bb60 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/kustomize@sha256:14b8b3b8247f889ec5b362da803da353a8226e100dd89ff086d4191797ee9da9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/kustomize@sha256:247d494e4ac3f93312865ce684df2f4fbb9b614d8cf9534cdd44f1bd6d171096 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/kustomize@sha256:8c88f667740ca8b37b41ad3738f699c1f3d3fb319ccd95654a81affc47973516 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/kustomize@sha256:ef5aadc0d92d96cf12dfd07af335912c28e8481fa8254e0120a60002516768c7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/kustomize@sha256:36097157f22bf530b72462d13930292671901c0227b7ca29c5bc0f1c2e48ef35 |