Sign inSign up
Docker Scout CLI

dhi.io/scout-cli

Docker Scout CLI 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.23-debian-dev, 1.23-debian13-dev, 1.23-dev, 1.23.1-debian-dev, 1.23.1-debian13-dev, 1.23.1-dev

Index digest:

sha256:8ffaf395b0d97f73caf6d9bcd70ddb676409b1354aa1b5f57a39f0fca49d727c

Manifest digest:

sha256:eb6ebe4b9d64be1000e4e41eec78a8325fb4e70cd32c482a5e76f6e5725b8bde

Size

132.35 MB

Last pushed

22 hours ago

Vulnerabilities

1
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/scout-cli:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/scout-cli:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/scout-cli@sha256:afac1dc8e528ebd602e0029bccddd8a45f7b3e3c7c8ec5fff5feb09d2c680a71
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/scout-cli@sha256:445539d40c440d597221ffcd1b7602c54ac8c0bed448e5cded80343542337f46
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/scout-cli@sha256:d69b40cfe61450a06b16c2a68357098b7612d8e7066f98cf48176244b65346dc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/scout-cli@sha256:99fa0ecf9807ed053a73f451892fa30d12d6845c8921059323e13c190aa9cf9b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/scout-cli@sha256:5d4edeafee612734c63aef8abb9c79c291488ca18eb28052b224d1be65f63ee9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/scout-cli@sha256:786d519fea40febdcdf2ab35cdafa4a50f5ead5a1bfcd74f962507a12441f393
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/scout-cli@sha256:44b1ef930d904b137c3c27daf4699cb8eaae73b6edb75963286262b6e8ab0d8f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/scout-cli@sha256:1ef616284bbfb69e976433ef4191c28d4452be86db87b356084b6f7d76c0fb23
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/scout-cli@sha256:269a4df3c33c9003ab04f688ee9ab1c214aa71b581a0281deed19edd19f7579f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/scout-cli@sha256:940488f924bd9fdf1e9e42f1324f944be5372e31c716f824a9f7a7fa2dace8ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/scout-cli@sha256:b85d34a634807160c45f12db4f24034ca3a69d18832bee35ab1930c408862554
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/scout-cli@sha256:17317d8cd097ec65f47b4158454af5a35723ca0f7541f296a52a52f0769852ce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/scout-cli@sha256:94133767e826a7b2a0cbd1ff48de1ef42e42a4577a04ae64c5fa8db4ca718c3c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/scout-cli@sha256:d6c8560125d749f5bd1a89574f8140f3700b2770f989261b64f0b79c0c5694c2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/scout-cli@sha256:f4e191b98ef1f860f8a818e22c51bcbcbf72d9946febffcea64fdee992afbd53