dhi.io/openstack-populator
2-alpine-dev, 2-alpine3.24-dev, 2.12-alpine-dev, 2.12-alpine3.24-dev, 2.12.8-alpine-dev, 2.12.8-alpine3.24-dev
sha256:d2afcb1719f1975b96ac1db62bb04d07e74aa129d1674a348352ce68864c0eb8
Manifest digest:sha256:a778366033d342d0768144dbb8346e59305fcdb831645cff35064e5d51e9c17d
Size
26.92 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openstack-populator:2-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openstack-populator:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openstack-populator@sha256:1621377064c9da4b3f2635981e88c848c150bf6af6ecc1ca070253a31797e6b8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openstack-populator@sha256:8993a7e34a64e9c007a304af74c23dd53f7c1500d3712f857057d480551ce120 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openstack-populator@sha256:b288ebd6402bfc5fa1c6bf47b78f5eda3fc3a47801a48627f2b86eca60a79f75 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openstack-populator@sha256:cc79e63da2f0a4d97a96639aa851970ad1b45d7ccbcc0968250a671bdd256ce3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openstack-populator@sha256:e494478631ecc85fdba790bf9f1d5ce2eafebed07492bacef39c8e79afd576c5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openstack-populator@sha256:feba8008196dce11fdc74dab9ec6affef757675ebf4a7e82caadb6a62993e560 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openstack-populator@sha256:02a4ecbb02cf3e66e1453d51da85726468a1d22cd8722f12568c590e6a582e20 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openstack-populator@sha256:1a33d29a6c58ad00ac0f2ff145f37d1c011a0480d21004fea6059398b18a0eb1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openstack-populator@sha256:bf4346f0a9f92479db89c983fa50bec03bb924338067ccc9176576b4edca5fa6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openstack-populator@sha256:10f62e6aa3ceb41a20e49e70125648beda61ed20cdd53e7db0b40cf59556e526 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openstack-populator@sha256:6259c4ce55fc506afd08686fe6b8833c170e00d7fa931a68ab56a6b63d64627c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openstack-populator@sha256:f518e06ae3251d0ef3e077ae55e421d8c7679b2f36089ecc5b801f5a08c0a9ef |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openstack-populator@sha256:29620d2904ee505669adab28ed18dcf6b3dcbbaa2022fc3a84876f967c54d76a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openstack-populator@sha256:45f37cc0beebc38cd2af137386783ed57520e1a6d7ef9b449783c58b56bda20f |