Sign inSign up
Kustomize

dhi.io/kustomize

Kustomize 5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips, 5-debian13-fips, 5-fips, 5.8-debian-fips, 5.8-debian13-fips, 5.8-fips, 5.8.1-debian-fips, 5.8.1-debian13-fips, 5.8.1-fips

Index digest:

sha256:677f30b2d4c85aa9bc92617effb0fa9a08b73426448c5a3dc8ed689c316c63fc

Manifest digest:

sha256:5ed3203761774ca0a57a94524842363c9bdc5a4be48c40a89e1b8f8c21f248ce

Size

40.44 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kustomize:5-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kustomize:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kustomize@sha256:22993a88412c1d7786a24c42a0070ae94e392cb84e9ceb65758da4db0fb7708a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kustomize@sha256:9f207a1b3cd18a447715f3dd28eccfcd88715a209bcade184cf5eaaa866cbcd2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kustomize@sha256:8b73d34959878e37de9ba13acd6df9b8f692ce83ee71d539bbe515542f913665
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kustomize@sha256:30338884f312441f62702645db4c805b86172d8c932f40729bd61599b7e0698c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kustomize@sha256:22940846e471e24df59853dac1e5981c32a5a1e8efe3b06251dd9bdcdec21405
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kustomize@sha256:029797b8f67bad65e4baee46818b55ee446089511686e51e98e9609c2dbfcff8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kustomize@sha256:2b069d1f1e1479c48ae7ac4cbbf864b865ef05973f3ae1900053a029d29d877d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kustomize@sha256:288c8f408567fcfef402374af3d78cec7714d758b9c45537a1644bbb215b05d1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kustomize@sha256:9d586ac9855f27693cec9b19f16886e455c21939659edbbb61070d2b5f8aba93
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kustomize@sha256:08aadd45943b063dbc437fa706a9cb4503abbf76e084907996ffefd57352ece2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kustomize@sha256:0064e83655aef7eaa7eff1bea2ff3e69255171f8a1a988d8b9916ca0f7de32e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kustomize@sha256:ce09af755a0cce949abf8af5f274f29ecff3daf1519111adb06126cb5aae611e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kustomize@sha256:dd3f05fdbd71cf84cdcc7e03ff34a80b98622384586eee21d51364b9f239ce02
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kustomize@sha256:829200a981707d7065513f966547b37b190a21d87ccff40e9360fe536027e817
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kustomize@sha256:4d9704313fa69df1afcb3d3d14f635047b5af04a6fb113b93e4ee0626b692737
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kustomize@sha256:30a81d3be0c6ed9874e62cbc350f08dc125f366445fa2184bf82b41789ee9afd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kustomize@sha256:229aad42266e2b744748519a1f275be46f5d416e8653dff312e71c52b6453f1c