Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.13.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.13-alpine-dev, 1.13-alpine3.24-dev, 1.13.6-alpine-dev, 1.13.6-alpine3.24-dev

Index digest:

sha256:68325b1a3b7b32dc4ba67c95fb6d5e0f10c770fe9e82bca91a4f4efc20e278c9

Manifest digest:

sha256:4ac43c7b7e7e0c346b967d8fae2072237aad340d85d9fe73413a5711ca7ef754

Size

381.95 MB

Last pushed

18 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:f7212f32a62591fa53100b89515e9c87653a359ec5ee34c594764c96c98229ff
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:56e9fe696cb2a9aa488b938ccbe0d963352eeb0f84c6b40b0a101ae054d30378
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:182260575fb863163d91a985161a0b9a140febbe04ac3c88382aa073c7079e8d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:d9dd8eac31c930844095fb3ddfd37200084b20c9e23534886227fa43274c20d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:703ea2c90d350bb061dc397ad70758d5e66d314cce6f7972195428efcf50b7f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:98a80a847cc0680d9f2cc73e9fa1780db1c338a798dfed3703ddc6ed8e64397e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:aed3ddb993dd651e9dfcef8289f311cb931e9aee092d61c5bfce604eb0032790
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:30393b787ff8d58743ae17c20952babd953d286289ed1f68ce06f5431e48ae02
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:9f0a7befd663320a38955bbd2d19693c5f190b55915f17dd22503083c660fd10
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:895fd87a858dc99e1913090c116e736566bbb9f6e7fa76c1d9ae6107a35b4aeb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:bc19de231600c7814273ce5ddbeda58df507fb57ac34680cf81f89d74fb76eaf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:7e8b7f4ab3d8f3013155ee196165c8030427d6afb0184cce89b61d20b26fc26a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:c0a648daa0c50a92bcf156b588c5344ce57d12df59abe095aac9fd9c41e81511
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:ac8f19aeb3c368ff6f64f1e8beb067411cf8cb21b10bb377de99d07e1b471e46