dhi.io/openstack-populator
2-alpine-fips, 2-alpine3.24-fips, 2.12-alpine-fips, 2.12-alpine3.24-fips, 2.12.9-alpine-fips, 2.12.9-alpine3.24-fips
sha256:9a4aa1ed27d3864d9de7d3c53b5f2e95e6abd4c3c7b1ebbe5fbe8da90bb7f507
Manifest digest:sha256:1d2171010cdc9aa36e53843230ca8d763ed23d3aef5c984142d4ce71a639f924
Size
14.46 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openstack-populator:2-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openstack-populator:2-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openstack-populator@sha256:d14d1cdc225ac3c70f54733f64957c2ea68d49eba47889326556d8a43a65ef81 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openstack-populator@sha256:c35efdad7be2a177ddc26bf6b7cba63f5707bcab733feb63b94df7de9a1c0813 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/openstack-populator@sha256:25d30fad66a9fcd4cd2a8076c98b4661d3261df32fcb556af0e1d53830080876 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openstack-populator@sha256:539a638da4e052f3d2c1ed0bf51326b8585fbc4659dd01bf69a31a03d0999316 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/openstack-populator@sha256:b2815cbf5cd9d8c6bb842992d388b537cc9221e8971d149ee01cd0507a1aa8f6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openstack-populator@sha256:5df7255a5e82809e5cb6b0f6a5e6b54b2c3a6d61aed8fdac83bee348823a315c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/openstack-populator@sha256:778464a242c2414efdc450ab7e848b1b00951d5959b0050838ece1f11a9e450a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openstack-populator@sha256:5e27a22df1abb64b0fc31a15cc3feee38ccc5cd555dc9081b0813fb96b64eed5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openstack-populator@sha256:045082723f3a539d42b41e4f87704ab52d621a1a9e36a80a036e877ad08a47fc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openstack-populator@sha256:5f58ccd749f194083e548cbcfc92cd6b108c1a911a77791a8089483b4cfb5aca |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openstack-populator@sha256:26b0d4917ae716fb3a5275e9ec16f21ac91a7e0c557c6c6bc535148396e01617 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openstack-populator@sha256:d615875dee4cc3ad491574ba50b72605f648175cc8ec87e15fb578e2112453dc |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openstack-populator@sha256:b3e2634e36c43dae65b3d27e7d46246889ef348cb8c41be48df35885a68023d2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openstack-populator@sha256:232e41e6b1760c8f8787318fb8f0d4313999f6602e9ae53ab275866249f7eef1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openstack-populator@sha256:3e2470ef2b1999dd8182dd1d8585a523f14c5b029dab9e8dd303682d865af36b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openstack-populator@sha256:a0d8303cf8f67857b430c1aade47d24b4490647590ae5beef0005d138fec21c3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openstack-populator@sha256:23d754c162ffb51311d11e00b90644c9555dadb09cd5cbdb48829936cd86f6c2 |