Sign inSign up
Snapshot Controller

dhi.io/snapshot-controller

Snapshot Controller 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.6-debian-dev, 8.6-debian13-dev, 8.6-dev, 8.6.0-debian-dev, 8.6.0-debian13-dev, 8.6.0-dev

Index digest:

sha256:e64acf18929861b3209feb3ff95d56b937380e3064a4503016251d6d0e1867c8

Manifest digest:

sha256:d52bd85d75d0799e697c0389a0b90230b5811cbd7936ea00884631cd4128ff1a

Size

56.13 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snapshot-controller:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snapshot-controller:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snapshot-controller@sha256:9a3ab808cd3a649485e5c6dbd52cfd560846baf2c4f942526d5d0a2bd097aca6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snapshot-controller@sha256:d930569e4556d5346c2ccec3652e3bf39a6fc769041cb9870425445a09a90ad5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snapshot-controller@sha256:12368691b16062bd8b2168e9cc5311e559e13fa9303e08bd49feeb9a740107bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snapshot-controller@sha256:7afdb68af4e87002b27f291e9483060b6c481ca7d6f6b6c5b32f438d31db89f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snapshot-controller@sha256:2b57e4b7a7400ea0a34f33f2b23f1a614659b4dfe009eefa9f24fb6366040380
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snapshot-controller@sha256:5caa14c58b87b1f1cc4e7af8a35b1dc7f6f1e5264ec157ce36b7719cb8eda2d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snapshot-controller@sha256:46d1e4fdf1360364a30932665d951c0d851d92822548d142c7f093834658706e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snapshot-controller@sha256:ebb3eb47d6d9085de3be24464b88010c70f2100c554210ea83eb6e0aefc91821
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snapshot-controller@sha256:f18f9675584f3d41577e0cc6db581eb3e86ce5f64507edf5f18d4a2398c63631
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snapshot-controller@sha256:17e194516f70f1481541e991e772ab18feaa9c7fc5a3e1e14ac8071025102268
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snapshot-controller@sha256:441304e8bd108bd592627699d19dc51291b1427fee6f575918edacaf309d0e81
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snapshot-controller@sha256:a55e1759556df28ac8fdde509203015b0e4fc5af5a1ff87a78f6d6091130fa0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snapshot-controller@sha256:bfe1937c4f8536ada215d006b83ca142e8be3ba84c6cf891406003ed23463088
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snapshot-controller@sha256:a3cb810f54c9a64a6282907c1e3ccd92b05b14b888322cd5beb14c657da693a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snapshot-controller@sha256:51ebb067a014937a7cee662a79991d3018e4eceb6ebb76209ac90acdf65d7316