Sign inSign up
Docker Scout CLI

dhi.io/scout-cli

Docker Scout CLI 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.23-debian-dev, 1.23-debian13-dev, 1.23-dev, 1.23.1-debian-dev, 1.23.1-debian13-dev, 1.23.1-dev

Index digest:

sha256:605b0ac4fa9796bb698b80b9dcdcb1f298801e5d7e67d75e13bf1974c1fab4f1

Manifest digest:

sha256:d98b66456232150f87d6b765a1384bc52730de5b8e9fc5c43c03c08902feb922

Size

129.78 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/scout-cli:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/scout-cli:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/scout-cli@sha256:38b5024305a1f6752114778969f9050b35ddc9710defb3b95a08a8dc784d9ff0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/scout-cli@sha256:9da35e8a065600a63a86fdc21fcb4a1fd2e760c09855a3d4c82f71a0a58d8618
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/scout-cli@sha256:ca6c85d32a31a54725d8a5f6d653c32bd259c23102d75956d0dd0c5df0f78f14
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/scout-cli@sha256:ca806f3029edbe99f034510f33a6ff89d79d8f069eeaec3732e1a15d3b660a8e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/scout-cli@sha256:02718e47818a8583e6241429f533f8d8004068483a3b49e52b01c3c83bf50aa8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/scout-cli@sha256:dcaa0b2286a104967db018974f1da5057a24b2a51c752ca7365f9481360be6fb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/scout-cli@sha256:e20f38e47a50938e9772041d0170ace188acd1c3e3d3ef14370837eb04bf3de3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/scout-cli@sha256:34d9218d9a0dfb56ca006ec8f8ab5eaf48748f6d20f104634b2695de7eabf241
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/scout-cli@sha256:4fcf911300599aca07f91e266694abf5ecee6e33959ff3eff1c1fbce8374ace0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/scout-cli@sha256:0d584b4bb932e61c5294e7dc7e66b4d5048accd7a68f2d79a00bb136c79c8de0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/scout-cli@sha256:6a449f8bd36334bd6a94954e07454ff2f44d3e56b786218ea3b9a0da8851f1aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/scout-cli@sha256:cd37514b4078db2a144d7b9cdfc95cc8cf367d54085fa8ba47081f45d1edfc83
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/scout-cli@sha256:8e16be8ae1a36bf10e702589aceb4c50e8b79b3d4415350373980edc5523f289
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/scout-cli@sha256:6ec1fd6867a309658dfb852ad4d32448388ff3ff75de0a502a9baa5c401d7b3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/scout-cli@sha256:220d6b200c75bb8b75ed475d9908079f2b1bba804eeb4d226916bb06b947b345