Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.12.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.12-alpine-fips-dev, 1.12-alpine3.24-fips-dev, 1.12.14-alpine-fips-dev, 1.12.14-alpine3.24-fips-dev

Index digest:

sha256:de90e95e41d4472e40910e8b8bdc388b9e6c1dd246ef14d1b5e6ee2be5f360a2

Manifest digest:

sha256:dacc017297aaaf02b579356f67f01e1343a4c6f3b8fc9891a65ca0b987692abd

Size

374.69 MB

Last pushed

1 day ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1.12-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1.12-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:a4e2a1837269a07d0f257f98f25277063866b09378b153c3ec767dc0aa8def7d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:dc06593931eb9e2f00f9fdfcbfba6ba192c3000407ac1422973cd9c209c72352
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/openmetadata@sha256:b39a8eaaf645721a4e4fdaf11960a24ca7c64154721efedd3be57f525c5ce86a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:8f490a852df7043c1fee03f66c0745199a3bf268e2db8ea9abf670a94542e62b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/openmetadata@sha256:62d792fc06ffc04a5de31ba75c779eedb003b3503d60fc2dc7b4ae4fd18ea462
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:0838c655aa847b085a964a1cd183ab1d89cb954d43044505dfc4b6195d53a32e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:4ea76991ccb4dc0ee83b513e48a7d3931e4d7c8bfd2cd72c94e6c782c4dbeb8c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:decb7821d59dd6a2f820511710121399832653547393e8a743dd232c7d1ecf4b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:d4dfb1b9e7611a13b0c49352252c59bd685a4ce18fdc68d28c9529b550cba4b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:d4301bac09c14ae423410e17ae2e141ec253feed6a1e392c75999963d1cfab28
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:92ef4a98591270e1e173c61d16eba1169f3ea7c725fc7f8e04e68985944a68ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:db5451627dcf3fd65b9feadab7e54343e38417cdacd6471e844aba05bdabfab4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:bc27265e5f685ef20647eb81c5bb85d5ac9789daeee7d7c69896cfeeec68cb77
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:2876bbb082d8d09c1494e0b4763a1ffeb3424950697275b032e5bc79a3515ff0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:94d758a3e927c0b74b744808bc4035d2264d12330ed31188a5809df3164bd4a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:90a7a3905c68ffd2b46802da00bee85a959e43ded8a7618851a105fa8cf19ee8