Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.12.x

CIS
linux/amd64
alpine 3.24
Tags:

1.12-alpine, 1.12-alpine3.24, 1.12.14-alpine, 1.12.14-alpine3.24

Index digest:

sha256:2e50174da9c74325c1f9888cd993d3221434add7657d58132afb9d66c1cde6ed

Manifest digest:

sha256:2b483b498d43349d374ee4b3023b495bd8b11d4d8ddc2f687b9da9f7382e6cd0

Size

362.90 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1.12-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1.12-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:ba9e675887ed1993817be9960954296d58032fac9a949eb9102708eb22f635c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:978e946285d7d41b744c4b7b69b46b4126fd046aba8e8e5c8a101cd760b09f4c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:a3d85769f0a24fe92d6a0f410b0ccd4ba003b8921667fc63b18c7377cd1747ed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:fedda2aa3b5bc1786004e8c381e41576bb7c41e1c7c7d5bccb4215dc534b2c45
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:0a6468b6e05010a6ff9df8d6f7587ae57f5dbc126ed140eb23886e03f1274c63
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:4638aefb658493a6ae6d478acdc32836d3f83e7abc40c98756f7fdc4eba1897c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:038aba4b3f9a385817204541c82d0b61721a6c8868b2aac36c2ecb9de6b7b512
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:173d635f7cf3a0b9e2e087562c7ed53beb6c169fb35b99cae857e162d3e66eec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:c427368d06e28073f3af421135aa180424d581800d7fb851a04f821e8daea78f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:33456c6a395b03b20b5b3a83f2f0cb550cb66a2df2d3ee949f070f95f5ebaa05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:fe7614469dfbb9bcc5c11615fbdadfdcbb010e306f6a63827916cae78fa6eb79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:0974b6fa7e420ba215afd7abdfc649d5edc153c3bddd69ac9516f0eb7f8a8eba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:1d6dff6c6eef1611062b51a667685a27bc42831a470449c3f4c4f1bcdc823b15
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:0e6215f801f5b39fdb1d49676d9f01b7ae420bd6f88e7043c27a0d5eca48c19f