dhi.io/kustomize
5-debian-fips, 5-debian13-fips, 5-fips, 5.8-debian-fips, 5.8-debian13-fips, 5.8-fips, 5.8.1-debian-fips, 5.8.1-debian13-fips, 5.8.1-fips
sha256:677f30b2d4c85aa9bc92617effb0fa9a08b73426448c5a3dc8ed689c316c63fc
Manifest digest:sha256:5ed3203761774ca0a57a94524842363c9bdc5a4be48c40a89e1b8f8c21f248ce
Size
40.44 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/kustomize:5-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/kustomize:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/kustomize@sha256:22993a88412c1d7786a24c42a0070ae94e392cb84e9ceb65758da4db0fb7708a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/kustomize@sha256:9f207a1b3cd18a447715f3dd28eccfcd88715a209bcade184cf5eaaa866cbcd2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/kustomize@sha256:8b73d34959878e37de9ba13acd6df9b8f692ce83ee71d539bbe515542f913665 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/kustomize@sha256:30338884f312441f62702645db4c805b86172d8c932f40729bd61599b7e0698c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/kustomize@sha256:22940846e471e24df59853dac1e5981c32a5a1e8efe3b06251dd9bdcdec21405 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/kustomize@sha256:029797b8f67bad65e4baee46818b55ee446089511686e51e98e9609c2dbfcff8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/kustomize@sha256:2b069d1f1e1479c48ae7ac4cbbf864b865ef05973f3ae1900053a029d29d877d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/kustomize@sha256:288c8f408567fcfef402374af3d78cec7714d758b9c45537a1644bbb215b05d1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/kustomize@sha256:9d586ac9855f27693cec9b19f16886e455c21939659edbbb61070d2b5f8aba93 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/kustomize@sha256:08aadd45943b063dbc437fa706a9cb4503abbf76e084907996ffefd57352ece2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/kustomize@sha256:0064e83655aef7eaa7eff1bea2ff3e69255171f8a1a988d8b9916ca0f7de32e4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/kustomize@sha256:ce09af755a0cce949abf8af5f274f29ecff3daf1519111adb06126cb5aae611e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/kustomize@sha256:dd3f05fdbd71cf84cdcc7e03ff34a80b98622384586eee21d51364b9f239ce02 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/kustomize@sha256:829200a981707d7065513f966547b37b190a21d87ccff40e9360fe536027e817 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/kustomize@sha256:4d9704313fa69df1afcb3d3d14f635047b5af04a6fb113b93e4ee0626b692737 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/kustomize@sha256:30a81d3be0c6ed9874e62cbc350f08dc125f366445fa2184bf82b41789ee9afd |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/kustomize@sha256:229aad42266e2b744748519a1f275be46f5d416e8653dff312e71c52b6453f1c |