Sign inSign up
LocalStack

dhi.io/localstack

LocalStack 4.14.x

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine, 4-alpine3.24, 4-python3.13-alpine, 4-python3.13-alpine3.24, 4.14-alpine, 4.14-alpine3.24, 4.14-python3.13-alpine, 4.14-python3.13-alpine3.24, 4.14.0-alpine, 4.14.0-alpine3.24, 4.14.0-python3.13-alpine, 4.14.0-python3.13-alpine3.24

Index digest:

sha256:dc49c313cd2615759e81ce1d9b7e227261a8f7408ca856865e96e06cd84c34ec

Manifest digest:

sha256:fca60fe52a11472a3d25c8303cda40511754d8a5d4ed6578b9d19e257264be2f

Size

83.12 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/localstack:4-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/localstack:4-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/localstack@sha256:1efb618d617c529f7ecd1f53caff3d37ff3523b69cd7733dda0e412197dd8b23
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/localstack@sha256:ce024e47dba423d32cf26048fe76abfba00a9d0118a5662f38ae75da58165d81
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/localstack@sha256:7b513c05b0c1f3d971366a4090964b0e9783c90d7838a5ae9ae53d6374a4e992
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/localstack@sha256:616df3eba578d1313ae9f6eefc8af6f98774f954538fc5c4bf856cf6978ea53c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/localstack@sha256:47eaf074beaaa726c8e0ece7032e683c8bc32ed87759e0ee77460f0cee131d54
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/localstack@sha256:8b4f18844df91c6805aea78f25dfefdbec113ab9c6cffabe37960690ad422fcc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/localstack@sha256:73be77c15e87b6f20600503c2a33f0d0780d487ca68f391d114d9630029c3c45
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/localstack@sha256:06a527dd095453ccf9272305e7d5bc11a716ce2425b492b1d8efd52bbb7981a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/localstack@sha256:1fa46fabc30dccc665449c0fb202fe16486a93308b58d7527d20552919be2162
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/localstack@sha256:3592ffabf810a5e1e6f3b12acea010c998e0748c330da4931efd8732756f9aa6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/localstack@sha256:46810b879827493c554bb4776be34c6544afad322975099c7d404fef1879ea58
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/localstack@sha256:a783d33663262e4e3996c7c2b08e8e584ed06555b81f6b994ac9eb186cd9ce45
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/localstack@sha256:7dfb6f1126999a02a0fdf2a2740bf33a67e2cca0e4a751b2a162d7d67068b066
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/localstack@sha256:eea20addb0ed4641152764c93ae87cc8fe9d6e9949f8c59adce6749a1d269a89
SPDX SBOMhttps://spdx.dev/Documentdhi.io/localstack@sha256:7c238437c76e6cdfcf142f69b3383608890f500f8e328eabc0ca0876fbea3b6c