Sign inSign up
Kyverno

dhi.io/kyverno

Kyverno 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.16-debian-fips-dev, 1.16-debian13-fips-dev, 1.16-fips-dev, 1.16.4-debian-fips-dev, 1.16.4-debian13-fips-dev, 1.16.4-fips-dev

Index digest:

sha256:9866033c4f27beac88583b507ddfbb155a27e3fc20ee1af944c6860ca2ee40b3

Manifest digest:

sha256:b2b8c84de6a03d028f3d1ae91572753b969589bd9754e98730aea43ddaf462ec

Size

90.63 MB

Last pushed

3 days ago

Vulnerabilities

0
4
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kyverno:1.16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kyverno:1.16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kyverno@sha256:95cb5e21733816ce3a7fdb91a4c5ef7899b8a8a49390155af888c69d7472a728
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kyverno@sha256:6c39b307fab1c519701c62841b5e5e04cccc02cdebfbe372b5340a25bbd67414
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kyverno@sha256:1cb7870a423815afdfaf1202ef85ec87493d0e831ec76485ca2a8cff4e313047
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kyverno@sha256:bb7fe1085e05a5dba63beba7c51ce6b68c4fb14d77c8ab481556d2c7fbd3af9e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kyverno@sha256:a7a236abbacccce03796435a60bd98700991f6677d840762f5c9f1c5332250f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kyverno@sha256:33dde746dc0d17664613cb366bb9e22b0db00c1829dd2e62a70f2645211a0c2b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kyverno@sha256:31df98b69318edab7e19cb63463726551f69935b1a2f799e5efaed7101eee55d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kyverno@sha256:312748f8d6ecb1f4ff7a3c134affc340831c852d94ee6f1935b5c1de174ba815
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kyverno@sha256:818272939ac7583379f7e4b5df66d0210e5455a36fb91a80f61437f4736bb23f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kyverno@sha256:f6f07bea40b12840667a45efe216243e6a23f31bd3d579837685d3a4d6d9dcd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kyverno@sha256:1bac16ea8655bd9636baa728222be10cf778005755f82b8f044b513ecf54134c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kyverno@sha256:70271300d4a525c9d740615a09d09574bc0caa5be3cc0d50d046fd47d4ab63c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kyverno@sha256:ae9a4d9115f52deba5879c642fcc0aebfb7b55246ad4abffe207dff046cf1694
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kyverno@sha256:15b2c0227e6b006ae84c3338d7b31807bc84aa8edacdaf9cd5837abf9da9cc1e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kyverno@sha256:dbeff88f37656e2741afdcaebf20b9632a3f6c5a7a8291165c7b96a96e2ddb05
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kyverno@sha256:193c78c248a3856f35fcdfaabbba5a0a4798822bd42dabd6cb1a968efa5b63ea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kyverno@sha256:38bd9b17db6a4de352f03d73166d2220bfdb2482442c5d09b0f3597cf399d4f2