dhi.io/ovirt-populator
2-debian-fips, 2-debian13-fips, 2-fips, 2.12-debian-fips, 2.12-debian13-fips, 2.12-fips, 2.12.10-debian-fips, 2.12.10-debian13-fips, 2.12.10-fips
sha256:489891d9c9f399de84fea72b0512f11fae3417264cdd34233b8a2ff63ca9638e
Manifest digest:sha256:9d99108ebafabc753580bc95b98a8bb4c42f9bcc4b8198631f26ca8e06755af3
Size
32.93 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ovirt-populator:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ovirt-populator:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ovirt-populator@sha256:f2196c55d878fb5e06e7857e3200b5f30647171b8f323b5a634914a145068f5c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ovirt-populator@sha256:2b2e09a0547d4acede6bedb71a23f33d0d96d43f85b42ccd369ed478544cfb4b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ovirt-populator@sha256:278668030eef79ac95f21359a12e6f06e021b7136ffe7b323827b8595cf7bf0b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ovirt-populator@sha256:18bcccec495be81e9746342e48ba222308e752515e65c557d13516fce4d79ee3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ovirt-populator@sha256:a4d17bdddda126e57459e1aa60f5803ac847a167519f37732dbcc5d164681df0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ovirt-populator@sha256:d015971c2e3b21471135d80f2a8d6ed083596fac9765fcfa432fc49dda3554e0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ovirt-populator@sha256:f484dcc52639d05751bda12d6d736f41534c7f6eb128f852619d5420d31bfc62 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ovirt-populator@sha256:c8a2354c9059fba01f599e9df812dd74879447430f53bd44b8b84becb4728538 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ovirt-populator@sha256:343214082a8fb6c2651761c5f5d10d512a95c953059892a09c0229a1360bbd86 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ovirt-populator@sha256:4014cf2c62199bac1bc66f005d110f7ded3226c85675e0bbaba4d5eeea9647f8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ovirt-populator@sha256:438119868b3c3ac908e092833aba950d8acd2b63455edc99ed0e07d5671d6dbb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ovirt-populator@sha256:6088a6406fc64244a89c318e91786e4b89eb682730fdd0d1dc4e60e6c5452c9a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ovirt-populator@sha256:3c2e0a57bfd28f37728844a404cf9c0300614b727d67fb0fbb9fac2c87d7c912 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ovirt-populator@sha256:99cd1e125ad080b9fe048b40d1203a6952a72ab43731bf44e2fecf531fabc61a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ovirt-populator@sha256:40faa0edbe4c1e479be16867f55e678be97c0ff9a67dfadd957c1ecdec6e09c5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ovirt-populator@sha256:ce24b2dd6a2a4aa1a37f471ae88a3001f12b8b1d491f05b175e43f881ed623a0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ovirt-populator@sha256:a336df28e3d8d60971763f5157dbe71d14201b2de67501a666c060c37ff3de1b |