dhi.io/rke2-runtime
1.34-alpine, 1.34-alpine3.24, 1.34.11-alpine, 1.34.11-alpine3.24, v1.34.11, v1.34.11-rke2r1
sha256:8c859b0c6b4816f9f1ba28e54437252b0cc93468c13a7e1f276c16451b38d770
Manifest digest:sha256:24f928a76bbdc9b4a2e82823271db14712c971a3f2f8cbceb76516c4743f670c
Size
155.16 MB
Last pushed
6 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/rke2-runtime:1.34-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/rke2-runtime:1.34-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/rke2-runtime@sha256:f4587cad1b376dda3d5db3de692f5d59bcc51b5caf1bc774106318d0297bf14d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/rke2-runtime@sha256:b9ac19108a03cfd64a62bbbc3d7171b19a9cdf64aa9525267f202add3e35914d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/rke2-runtime@sha256:46a0842298b264f68fee5f403ca7759b4575132c9c1beccded845de2c1064956 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/rke2-runtime@sha256:7552827dd4130ccc521615ca3562f6f391e683a7df29484377b63cae0242f18a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/rke2-runtime@sha256:e4d439a68c25206923af3bb7177dab845bb7aaafc972ea361753238ab48e2584 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/rke2-runtime@sha256:43bbe2504df742926c54f3eff1f9f817154520d8743bcd01c61d641729f13819 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/rke2-runtime@sha256:0e2e49942825aaf234a9090fd58ac48a45628d1db1e3eba937f85f239c62a9a9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/rke2-runtime@sha256:2a8215cbc7e713332faab2bf3cf2fbefb7c09e64d746577a5c4823df2850a7fd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/rke2-runtime@sha256:c1350b3bb5d5693fdbc30b3c206da1d7daf01834ffeaf493e861c8d96b40e2cb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/rke2-runtime@sha256:a49d93cdacbecc405ea87b90de3d44708d662781b769c61bb9d623d090f16ae1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/rke2-runtime@sha256:a6f248d29cc304353327508b6ae95d13a634922a42b6d5ae2182243a2a79614d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/rke2-runtime@sha256:fd4d79c8badce762efcdd4ef99634cdc687227da5983ce26104df74f58b94562 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/rke2-runtime@sha256:ec81d6a17407d0c6969e3d3336df166d4d09305469010a7797a4af7f1f2216b7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/rke2-runtime@sha256:7b027fa7dc6842d7fb8ed8d682e261841f8030fa5386a4ff5578726e337f96b9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/rke2-runtime@sha256:d83d71ba61ff37be5fde3f2421d47960d6173134fbd4ed630c24726ad7d3e546 |