Sign inSign up
LocalStack

dhi.io/localstack

LocalStack 4.14.x

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine, 4-alpine3.24, 4-python3.13-alpine, 4-python3.13-alpine3.24, 4.14-alpine, 4.14-alpine3.24, 4.14-python3.13-alpine, 4.14-python3.13-alpine3.24, 4.14.0-alpine, 4.14.0-alpine3.24, 4.14.0-python3.13-alpine, 4.14.0-python3.13-alpine3.24

Index digest:

sha256:2d5b4ee7f21939e81642452c58202cc3453190f23fe7ade824c4b059df99f5c4

Manifest digest:

sha256:1336008c00c838e56a328400ffe40cb7e9e7fb2691ec8378a925141976a099f3

Size

83.20 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/localstack:4-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/localstack:4-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/localstack@sha256:e53ec1724de6dc405cef3e684c1f0be4305cf69f7c9959fde4f5fda155e950b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/localstack@sha256:912115b40ed09468457449103c23639fad38c07e2ca4511f3896d9965ad9ab75
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/localstack@sha256:f9788c36d0b008c4d3d01da5b0415637d5597d29b61ff5bea60a19f739c48b2d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/localstack@sha256:6a23ad6f29e56e35423c631f343fedd6fb77a93bb28b420995598deae5e9730b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/localstack@sha256:6317bd918c9560a9331b9adbc8e8cea8bd7d314e4c676c3bcc9ad06b6a91ca8b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/localstack@sha256:bd9c155b301842bff94a2ddb556c250773c3e747b487436f7597d44c17d98219
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/localstack@sha256:a8df678b331accb7dd64543b97a9a0ec6e07650874a10b47e62d1c3cc8fa89a4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/localstack@sha256:7054afa895de5ac6dce98b50023714a1555c192f4c9c469aae9e22362b750bca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/localstack@sha256:117f8ba65ea138318da4f6a321575613a660177a1fc44ffe2fe9c0883bb0225e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/localstack@sha256:cb099078fce4f32b3fb2da7811950993600491689f1dd5b3c7c1feb2a1563cd7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/localstack@sha256:b7f4da82f3cf2d71dfcfb91dc4cb4626059826f65bf934d10bc5ea65b614bdcd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/localstack@sha256:19a214e93e2a4823b9a782a82c6024cfed681082f8b739157c595219a13cba3c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/localstack@sha256:3862039af4e7500bbb98fde9816f75e03123700d10eab012ec4e447061539c97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/localstack@sha256:b9f30d45e158725062626297e6c3deb8b21e8e3a4663a3b76fb9330cdc3ffcdc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/localstack@sha256:bb9a0f5dc550d96e048e7de7f90f99cf646e63eeb930340f26adf5fa72c7d20d