Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.12.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.12-debian-fips-dev, 1.12-debian13-fips-dev, 1.12-fips-dev, 1.12.14-debian-fips-dev, 1.12.14-debian13-fips-dev, 1.12.14-fips-dev

Index digest:

sha256:f413a8fc3a5ac2ea3a37a61cedd45a7ccc81e0e41428a8d2b7283f3f766da95e

Manifest digest:

sha256:feea1364095b53abb3695c4a233b6d60073a29f45b91c679d01de7c6ca02c1d7

Size

392.29 MB

Last pushed

15 hours ago

Vulnerabilities

0
4
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1.12-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1.12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:bf437e775f75180bc54cb618caab5ec151e590899dfe500c28c89eff1270644b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:df2207c2d3703068d2dbd72e7f1307bc3e68830f6996a5889aded23926dba055
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/openmetadata@sha256:700565222722c9a044e524cc92aeb867693b9174972cf4b5c8a5b404be624b9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:7105caca05128557e8d6b72790957b1631147358492b6189f4004d07763821a2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/openmetadata@sha256:5c1e36c19238b7e800d5e003bccb0792a97c3f2a803cb9127a4d0d117eb9112d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:578356553d9ee728e355c1b04d00185c35da8ead817586c0e4412e7660e26b56
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openmetadata@sha256:094f156f285763481be4950ac75ede20230ae64083b7c529edf37db268c395f1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:9dd8bf33e944c5d30141370b064d46c01b4062bbdca968012d12edcbd893a8ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:58e3d17eb77c8285ecd24c20f1fcaa2efce460ab368699833ce454743caf0399
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:a4984a40823751eab34ebd3cdf3390ccef6e565484f6cf55c155a08446d40725
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:00c2c003f397968e759787b12cd25273dbf8e0607514d4bcc70b9005407e3f76
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:a09b8ed0fa195a6dead5743aca8c590a2bcf343dedbcb2682d187f371ec2ce6e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:fda913e34187f35033bc57968eee3314c9b464ce6aa8cabf0e040b0ff3f8d0b5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:2cfd1d99103dc5ff236ca3882f167ad74cf93297bf5f684ad7a4eb86c7e32f13
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:67917c084bdc7e59984c51d375dcb104b442c15d5ba8d4288e3e493f97e91fbb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:d3ab75a08a7d8c8e8f7a559cd98a97b59266218ba4ca465034ae30ec9489871a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:630ab1563ac9685e4dd92de06bd92427cf696992c0d3f480328bb25181a429c7