Sign inSign up
RKE2 Runtime

dhi.io/rke2-runtime

RKE2 Runtime 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.36-alpine-fips, 1.36-alpine3.24-fips, 1.36.4-alpine-fips, 1.36.4-alpine3.24-fips, v1.36.4-fips, v1.36.4-rke2r1-fips

Index digest:

sha256:694ccebe4b74a943140a84d0128c1fd5f1eb59733cb5fdf703a5bde534b6545d

Manifest digest:

sha256:9344179d9e114517ba0d5d960e1e2e331f61248fb9f261b8eee5bf21a3ea6ac3

Size

157.98 MB

Last pushed

7 days ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rke2-runtime:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rke2-runtime:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rke2-runtime@sha256:189fd201584c4a9f67a3d21e86c3dd1b56b43054bf3455c7f1388f0f640e32d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rke2-runtime@sha256:30801867926a40ffea86df08a617be26a90ba4f877ed0332de009e5ea7437bb7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rke2-runtime@sha256:6a994f448924b73e997370d0c36670a32160ae9cec49a6e02da3a1c669bd0e19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rke2-runtime@sha256:392d89f76a421ddf47d74404937567a1345ae29ef5bbbdc9f3003aff21af9dc7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rke2-runtime@sha256:fe7682cbf87699a60569ff5f1849e8b2bfb11b049cae818dd5c26a1288e655fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rke2-runtime@sha256:8e993eb2a6609c33edaeb6bbbcde10702d20b2c4445f25ca2fbb391a911f8102
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rke2-runtime@sha256:4366af99fde59dd59888c54b36ac49725ef64058d9297b804e87a6d40064ae3b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rke2-runtime@sha256:55b3a06931f7f9668d39dd546141b7a30e80d803936bc80ee3672eebe03637ff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rke2-runtime@sha256:61d37f2ca93526d87f8c59250125dacc44d4b37f5fb860caebfb603ad2111e86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rke2-runtime@sha256:e63126df49f5e2a175b3fd992a8d419481cfba0ab0fb4c30f716793f5e602e6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rke2-runtime@sha256:c704c4ff4e0f19b1cb1bb55fe9652a1b8575b478a57fa6724490ea1b8e31bdea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rke2-runtime@sha256:b2909dad660133f407b50b6c341e577c708055a6aa63b575d48c15c1e734c442
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rke2-runtime@sha256:61f592894a578ec69748426439b9fd369e4b3e24aeb44e9134f2386167fe1805
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rke2-runtime@sha256:75e7638744839d5d5b6f288e1b59d1e251d0fb0dbb9b1dd0d4a537a587126e84
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rke2-runtime@sha256:4c0c55c08e0f9ece6dc9e477fdcd55004bae70dca5044db288b63928e86af5da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rke2-runtime@sha256:6c042e4a25a17d5100bdc70d6db73b813eb978a3ce3b5f4eecc93aa49328415f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rke2-runtime@sha256:8e350d0141f794107759cba1d1a8cc3d239e32701fa03451784c435e2eeb104d