Sign inSign up
NATS Box

dhi.io/nats-box

NATS Box 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.20-debian-fips-dev, 0.20-debian13-fips-dev, 0.20-fips-dev, 0.20.0-debian-fips-dev, 0.20.0-debian13-fips-dev, 0.20.0-fips-dev

Index digest:

sha256:e55d05cd5ebe58a273f7c61db49497c3c4931a517d1e500d669745147cdeb0e8

Manifest digest:

sha256:52c51767287f3d784d2ae6524c45e1bde1bf89a4659c34107fe5ad0402409ea0

Size

47.58 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nats-box:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nats-box:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nats-box@sha256:4127d52fd714d2bbdc5158ae2420b8de11ab4618dd2d29a702cc23bfcba274b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nats-box@sha256:bef82bd3c1c5f58d4f67514cb89b846025aad1dd6a753d656f30b4b7bb6bb559
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nats-box@sha256:8de5d7fece5cd85ecbca4274d5933c5db009f7dce68b87a079f2326f701d1610
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nats-box@sha256:6de671af72d49ef672c1132f7b930146a9d401ed94a63a331d5498afe078d1f9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nats-box@sha256:5ce90d67e7e1681d268f9b74960e620ff42b875c43c26befcff2b863ba95f21d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nats-box@sha256:0dbf4da5a2873acc8b46293ed285aad6e2d2f42be00b7704a0c212e1484c23cb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nats-box@sha256:990eec3472211fc2a77a870a02df014bdb9ff4d88a09e1d6f9b19b99552720aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nats-box@sha256:da083ed09fce4b13fcfe037803712567f2f06afb8144e0b615b766189a0e996b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nats-box@sha256:f6585db37b0e3f6de484a421cddbb357be5be16446b9077b0d2faa17e3bb5f32
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nats-box@sha256:32ff71a391d1536fb674f65df3a6bc74f593d993facd8dcf57b8d3f24ae269e2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nats-box@sha256:adb0d5eb2e9dc7ea055041bbd308b9a6dd003a0159760092ba7d9d75864f61a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nats-box@sha256:c4ce3f04257b725b1ec4204e3d8b635b8b17dc2024f55a4029cce6acd710a250
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nats-box@sha256:39991cbc34a81cafd5fbd4fa1b9d509a3756be407accb4db749eb48b09fe8091
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nats-box@sha256:8e1c3fb318283e9dc2ad88478a3802978b2f6420c583bef131ace6b9454ec33a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nats-box@sha256:5259974e40cbc25c5cfbb92249d423b7e566d3a6e4dc44b978a3bdd58aaca2d0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nats-box@sha256:9b5589a0f5c5dac62910c0ee3a6802edd4f00594cf4519ce32bc560d3b336728
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nats-box@sha256:1aef43ea0c85a053925f0cf684fbcaa420b153f826b32fcc8a20a93c9c758c2a