Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 2.0.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.0, 2.0-debian, 2.0-debian13, 2.0.3, 2.0.3-debian, 2.0.3-debian13

Index digest:

sha256:d84a31876255b2198987ff02db9c54bb06403fad4b0a02dafbb05c813a326b16

Manifest digest:

sha256:20d3bded86d571405947e15ecf1df915edbf24f536ceeaa86db056a381c5974c

Size

425.80 MB

Last pushed

3 days ago

Vulnerabilities

0
5
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:d471c20ead1a3c4ccb787679f72cc172fb42ec797f676fb43399d179b749b7d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:b5263bcb56a94aa9c2ec2ddcc07b46dab86868760225879cc066042794c70620
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:d2654e860d7d9e84fc3dd4db327ce41d8316c53089b58605bf41abf70ba86061
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:57aa97b1c5b3257c6d792c26a50d5c6fcfd3640c61d88261eaf75ac0b51f213b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openmetadata@sha256:5f073dfb24698f23cf74653487e1c38e5e7598e9a0b26fc6c14f629cd34aa74a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:c1a3e31653b7f1d4ac5e6e536e877750d002960b0dccc89c27f355f1d742326e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:2ae8a3a5adf3488114e5c13e8b52a83c0a3d46020b65d3004c21820e3962d226
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:a794bac3796c85e7a0df700b7c2591fc596abad96cfbba85ec0b5a7bb974f965
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:6cda8f0b69ec02966dbda45518b84eb34a276338e6bec57b1fcfc4879e429022
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:5c8cee62cf3063e02b5b6ad60f355d11b87ceb879291b7992a358bc0ab5445de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:8c33295af698770263849156bfcd941c7edbf5d50823db6ebe93bbeb406f39ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:79e6e06ebc174abd0c48ef8f73e4b622ffd703c25f47e281fe1a0406e15af103
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:752e8fa01f47c3e5c97b2dd695a2b5fcf46b80a36259b6fcbf67b5be1e6a47b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:43384d5de16a0d013008dd98c6ef9c63cdb497618f1840b2d8405aa53f1d4eb5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:a298a2c056ba080802ae019280c681054ae3783a7cb1952cbcc89f44d9aea520