Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 2.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips, 2-alpine3.24-fips, 2.0-alpine-fips, 2.0-alpine3.24-fips, 2.0.4-alpine-fips, 2.0.4-alpine3.24-fips

Index digest:

sha256:33ee1a6b9487a16e004f010ff06a5f71c69d0d6d00650e9d8c7857585bfc68fb

Manifest digest:

sha256:38da16be8f37e5ac25efa7722e844e753d28b30b193959a15260f7d858e7fcc2

Size

428.92 MB

Last pushed

2 days ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:2-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:2-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:2cc76e9159848c0979a8d6a8c5428aa5ac189175f12be8ebb087d7027c72953f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:98918d5527774499e2b596a7d2391c52545ac45d4a1843e98bd80e68c981fd7e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/openmetadata@sha256:79d6933711d74665b24e9d09c570ed38c479c70b54dfa2f36ec9060623fe09d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:d02207492c210586df38c9142e61999b810f4f03e0ad19fc9b1f4841cec7ce79
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/openmetadata@sha256:8ad2edd78195ce0ac6f6c270c2c6848e1b8ff02fc0b62129e922f00da6b25e86
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:047be33253cde662d3572ef3e06c03021d52520f0bcc7858f5b1b6c497318b0c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:7c083531ef8875dab2484c604d16a369c5bdbb9476e5926226d8c0b7df4cd005
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:85af13f0fb566f3d9c235216c710012ecfb25959e0bd2708e683d58ccc53a739
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:d0378e5184cf9b5ecb4526532e515fc8b2b101b9067dccef048890bb8f963724
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:cec6e4b8a9d414d3f3392fe2ab83706048d8fcd254938d06d8889d0e660723e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:8d6aba7a2535cc0cf643c39a737c987f6e9a9838c51f0836648d56e660fcc855
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:e29111db9353de432f9bfe305d46a5ab4db72b6bd099dc627aa6b4e21ab542b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:634a1142ef51cd1726acab4b20b26e5b8abf58b5d042f339df0d8d3bd8b574b3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:0f34c0c8cc4eb7d565055ab6675ff903ae79032ec64090ba0e1ab8f344085f86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:ab27114bc41f44ba623d63268b7621554f09d2a63a6a125eb6ab1b7402c10201
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:c7bf2f9e43f934c1569842b42742c4d54e14c49be7ef58b8998c4f1efb8a9a71