dhi.io/openstack-populator
2-debian-dev, 2-debian13-dev, 2-dev, 2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.9-debian-dev, 2.12.9-debian13-dev, 2.12.9-dev
sha256:ddf357bed21770c53164f4d14fef0587384b8589555a4e07b452ce5d5921388a
Manifest digest:sha256:5e6ccf243f84832d78b96ae8a2d8606903ddf07105e26fcdb78798155a920f80
Size
44.87 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openstack-populator:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openstack-populator:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openstack-populator@sha256:eef5006b88b33015604e2136422f24ba82161aaa565f5dbab40940f330999c64 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openstack-populator@sha256:b2d531f57ddc93306fd0430860f85c05f744b1ac16b66e7ae879355ec13e22fd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openstack-populator@sha256:33793ae97227dd9cb4741e0730d22604e8f8dd84825c28577b81183254b0fbc1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openstack-populator@sha256:a6cd145f59f48a4d5d10fb64ee1c9eb9b4c510c90b193e97243caf2fb8b40718 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/openstack-populator@sha256:4adbf3f33d15c03c27e83110421dca44c4f6eef0bdd8d037657a5e4b38bae8e5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openstack-populator@sha256:a40fa58acd46d4b3d0289cc67065e31ececc1314d8c4a4aea4472ae7a4a08244 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openstack-populator@sha256:b66307f084f77e7910ac858bef24d658b069d3e3543046cb882e1a47ca0eee05 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openstack-populator@sha256:6785a3008c2566023e6ea7c100cedeb66709e9fc77d15122f8aa62e60213349b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openstack-populator@sha256:551f9830385940759a6f9917a891d730020ab6bccbfea25afb0a365010e17944 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openstack-populator@sha256:06887b36491e4e5aa71f3520e342ca016dd8a2caab5eb87bcbfaa73e1d718546 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openstack-populator@sha256:275b0f6fa19e620e04af8840674f33b62cf1f8d8b1506091453c3b978dc9303b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openstack-populator@sha256:110c8a94af1025edefb68ecc7ff85592f2c164399e8a56a2d30d177cc8c0b5ca |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openstack-populator@sha256:9525804e5b52a2c5f789332811f0a93ad0ae9f5941efc448801a36028b209e85 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openstack-populator@sha256:20d2fc6879e524b016110ae38b48fc1abc3cebe8929838a38788ac1a15027af4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openstack-populator@sha256:da09d4e9c947dc73417b1e0540f4ff1e4ba6da230df803475b4761e3cf778aba |