dhi.io/openmetadata
1.12-debian-fips, 1.12-debian13-fips, 1.12-fips, 1.12.14-debian-fips, 1.12.14-debian13-fips, 1.12.14-fips
sha256:d84b6f438a9b223b042483a85e76b4ea4b869e0fa13acba160a4d8add833536d
Manifest digest:sha256:b77227e5da6e7759edcce5b19be6c7d9c8bfeb534e46fb4bd0ed6c4a4458c6b4
Size
380.47 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openmetadata:1.12-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openmetadata:1.12-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openmetadata@sha256:2848c48e3ad546c7edac962d17fcb950ba683ded2a5760725b51e191e1e63cd1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openmetadata@sha256:8ec702afa10574b5528244a0377ca778b43678a6eb834e20025ee26f13dcd7d0 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/openmetadata@sha256:5cbf1885fc9c9dd28cf181159bf896b4272b35bd9c02d5f2e8ac4d4176435a1a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openmetadata@sha256:13ad16199c0f08123cdbb97508aba33defc61ff4a003beeb81f73f081ebf5adb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/openmetadata@sha256:540b63be14a8b4301fa9d9e11a1156aec3055d274e784850f843fabe9cbd9b78 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openmetadata@sha256:177d7757c5377d2655dbbebbd20d20a6e22c56585c3bf5c95179854af2946cfe |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/openmetadata@sha256:ff8de08b386dc53975aad61b9e2a516deaa89375febde4016f56f22486f646da |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openmetadata@sha256:ba75c98192cf60b5a9de495f1af97ff1ce5fa04e0ff968e476f1cb0eb92744b0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openmetadata@sha256:bc68bc34bb0c1455d5d38b78c05d6ca3fb358bea1e45de2c9bf8ba0a063adfcf |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openmetadata@sha256:a9e85244935d1acb876687fa648256ef7558dda912a23536a9b70fb54839b8dc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openmetadata@sha256:a185d4008724114ab955165dd0473eb79d5e04340eebfedcdaac8629b6d65e0c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openmetadata@sha256:ae9d6c7af1db354a1ada96074fea4c3c3b0e54af4f6a4f470a4af8b40d553675 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openmetadata@sha256:0a256aa791ce0589c0cc0c2a3a1d8faa88eaca96cd311bf06647336e3d678080 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openmetadata@sha256:6e26c087cd5d89d79d502ef309db1228f7382309e94f5a9a36767d84281dbf39 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openmetadata@sha256:44b3c8cc5f9605229ca1f400bdd7e31602979dcc2adcd7d4fb89bd61cbe7c956 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openmetadata@sha256:f275ba1183bddafde8e29dfc12afc3e5f052e778be7f388a243f0723ec4c22ba |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openmetadata@sha256:93ae0d5768cf62e624c6f788d82cd1f9dfada42ae19e202d5dc7658861da317f |