Sign inSign up
Kyverno

dhi.io/kyverno

Kyverno 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.2-debian-dev, 1.18.2-debian13-dev, 1.18.2-dev

Index digest:

sha256:755792e5a7321e700efc0923efe5ff5acfe2c4d1d854250dfe97c175f61d912e

Manifest digest:

sha256:b81f2b0b6aff175c92f9b7b0831d90505bc64972c1878c7c5a2f95710491fa88

Size

90.75 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kyverno:1.18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kyverno:1.18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kyverno@sha256:f4239eb5efb866ae8d1803d762e2890a5146d0ba9564505cd665f718845a0fff
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kyverno@sha256:3ae820f2014e418b89f75cb8e58280a2e2da7247b5200f650752c83a444a8df3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kyverno@sha256:079984da89bb7df28587cbf38764829cd78b808153d3f170e1ad52d8804086fa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kyverno@sha256:3f9015f8d5f1e36c12de5f642d888aaf37ac85501cde330ff0e560a76eda9a2c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kyverno@sha256:adcc3877f7d81dc273aa192e792a43c5cf70c413cbb002ba1d279bdb35462b8a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kyverno@sha256:0a822e36ba1fcafe041e8a77e55de4bf752a6c28cf16b0f58250ec1a34056bb9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kyverno@sha256:42fa149e7a3a4c01767ec42ce4bb0861e189f454a4c4deb97bdd20b1366d28cf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kyverno@sha256:fe5e09e9840b53320bcad92c26510cf98bf0892e94f04c884d7612c2eb1d7180
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kyverno@sha256:a7aa9a84511386436eb0f9f0332639c8aa9bc45f57dd480d19719171077cbf0b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kyverno@sha256:56fcedd7ba91e1a99e9865b9a03c7ef41641a920c48e2e3e9773115f611d94c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kyverno@sha256:031f2099753732d0c9166c292bf9ced41e20819eb49398ce9825aaa61f748ed8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kyverno@sha256:90cea8af231b355b88885a3b0b8b48eff83db6bd282e4727c3175e62f9876774
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kyverno@sha256:88e439f381256eb86b6795bd0d06808c4b09670372f51f28675dbf96948beab9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kyverno@sha256:1a9d41614f5169ae1fd0adf8cde767a6867c924e89ec5c74fa00f9fcfdfadb82
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kyverno@sha256:92e6623c31fdc9735c995f79d74a5cd28044a0802d225370292fc97acce5f1b3