Sign inSign up
MLflow

dhi.io/mlflow

MLflow 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.17-debian-fips, 3.17-debian13-fips, 3.17-fips, 3.17.0-debian-fips, 3.17.0-debian13-fips, 3.17.0-fips

Index digest:

sha256:dd71b486d9f29d90c74096a276cfd98bd534b9a201b385d0381deb594be3cbb4

Manifest digest:

sha256:cda851cdb2b4dd26d3d7166f008041d26dd20d6af10471501be065b66fa59e89

Size

152.29 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
4
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mlflow:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mlflow:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mlflow@sha256:c03e0cdc031085eed91d5ae7956798e56b7d7fb7276adc85667af6da517ac3f3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mlflow@sha256:6b7241d2880d090f2e51bd3afd0296f792fa5a6c030ddab45814f1668677aca8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mlflow@sha256:e650f44dfd249514740799d823afb2db747b36965d7808a59bb327c05716d957
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mlflow@sha256:593d8e412655ca47f662c1d4ff1610c3c2437b0d08607e9027e689cc174787d7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mlflow@sha256:6dfc10b8d965c302c5eb6e8f455618f422f4c16bebbda4b5a0ab3a65ef45b572
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mlflow@sha256:b2ba5882b9a69843f317a35181141e8f6aeb6f49b56aa5ade92186c4cf4e1ee6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mlflow@sha256:a412394639af9055f3bff059ee9382941a3ff74037845c764d433e7abf5499c0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mlflow@sha256:5688cca12f972f9a2e43ed30082561369010f9ef761fbee3897fa37ef525477d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mlflow@sha256:d34a47fbf292d07fff45201830dcc8da8d052dd849c40775ddc39e7221d303dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mlflow@sha256:2bf85d0012790dcb2ddca324ec71d473619d302e60bc814f63dd835ee5928103
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mlflow@sha256:f37c54cdf6f1e4704d523d7c9bec60244fa4ecda6169996a00792914e7c2edf9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mlflow@sha256:64049871aff153d7f42e7fe1875a4c9966f3d35b3f3525e557c2831499d1e697
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mlflow@sha256:428c5ba25d87b173aca983c075f1d1ea454963a9840be55636be0f118f7bcc66
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mlflow@sha256:e45c251165d348e82b981c161d8f063f552d349c8484701c19e51483a4f33bbd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mlflow@sha256:d74e7063095fbc29e7f61f4fdf5cb8e68ecc48cc8577b14aa9082377ec444346
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mlflow@sha256:da1a6ce787840be907ed2960c62e1c436d9627b99641a1e1427b3d6433383be8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mlflow@sha256:58c3f7444c9b5f16cc390af037684c700f8ec9ba5a6ebc48fd043d195d5e7d8d