Sign inSign up
MLflow

dhi.io/mlflow

MLflow 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.17-debian-fips, 3.17-debian13-fips, 3.17-fips, 3.17.0-debian-fips, 3.17.0-debian13-fips, 3.17.0-fips

Index digest:

sha256:8dc399e59fea07f6c8c117e3a36a7e54a66af5339bd9f649459ef5872c2b4cde

Manifest digest:

sha256:e21700803d41ee0d199411b8c7c5fe84aad9886ec9beb244e387e44e98bd5430

Size

152.29 MB

Last pushed

1 day ago

Vulnerabilities

0
2
5
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mlflow:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mlflow:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mlflow@sha256:0eb26f0de4053c12e35fe34fb223be83248078f54863a5a43d03d25943c1f21a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mlflow@sha256:ee51db8521fa918feab32a4b0cb89013a5e42fefa91b36a37c0833c6283be495
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mlflow@sha256:a1f3da4fbc3aa948e8d62b077ef9b3651ec6abdd9a78b6eb76b49949f2813d85
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mlflow@sha256:07f058c3457eb6f4ca881129a7ebbf74c1ade5def66b6712c93b5c2c100a2b3f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mlflow@sha256:795a6ff8803cbe0d6227f8c95668ae418238c4fd12de3a29d873940fbe9ac447
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mlflow@sha256:03518699ce84a403ad07c5a81c08eac5843a7f4fd525048f415d111a0b5fd43d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mlflow@sha256:59f02dc81a3bc7f7e7dc121e4ebbbde71a12e200273bdbb8fccd697058f6631b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mlflow@sha256:1474255bb4df647473fdaae2b1728b123b4094ec336dafe46c9a39b22e68b5e1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mlflow@sha256:5a3d72178c5e8b6fd0765e17bb26bceb1eb223d3f76cd932a58dd36737b2a64a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mlflow@sha256:0b0afed4e238a6860955ae7ef678db35028be6179e56e5de13293b20426a7450
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mlflow@sha256:0e4f291728c5d7f98526fcd5da058a74c3425cc8ae9d4b9e51bb857b2aa02746
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mlflow@sha256:35174de75c49c1e197933a9fda2471ded8b5762540c4f17d5abec38d35199e8b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mlflow@sha256:95fac59dffa192fb794ae72b0c181a656388b4c3df250dee1c48ec16dd5c7e0f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mlflow@sha256:49935a524f731895316ddb1ea66cb36aceed4750a159de7114b4de0be5813931
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mlflow@sha256:0d2221514007f1abf24bb10b43f6d26f59a03d8281063ae3dcd18b0db774f8cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mlflow@sha256:4afbdcbc62b998ca8f1cca206b1e3a8574f7778f2e6f9f55b78684f6c1a45e7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mlflow@sha256:a8ab84e0f5e957635e5acbb6537d004ec62df9667f31adbac13018a8afe6b27c