Sign inSign up
Snapshot Controller

dhi.io/snapshot-controller

Snapshot Controller 8.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips, 8.3-debian13-fips, 8.3-fips, 8.3.0-debian-fips, 8.3.0-debian13-fips, 8.3.0-fips

Index digest:

sha256:db0a7ecc97db62b24bbc50271042ef8ed1c9a154d0a93213617697b43c6b49fe

Manifest digest:

sha256:0923f09ba84aef94052125ad0a0c7aec2e4675fe7942f494c622048bd4fce5a2

Size

21.26 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snapshot-controller:8.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snapshot-controller:8.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snapshot-controller@sha256:26b921bb274d5c2239d908ffca89be0dafe2918fbacc61407c7b42ec4ed0a472
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snapshot-controller@sha256:936aa4a620ee629698ede8ef06b4eb1023d5256f9e85e1d27601a959bb1ed678
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/snapshot-controller@sha256:857b826c24672e2e2f028e1babf2d55f068777b0c0a013fca06988e285adf79b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snapshot-controller@sha256:c34872a5f05e7a09105a5769ba46ad65f9aa5c1d00f855b89b2edff0743e4b35
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/snapshot-controller@sha256:bf682269c6a0caf80c81e404cb8586212034d9ad152881ac03132389025fb70a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snapshot-controller@sha256:19e2a0f2d5eb63f685476c837ada6ef7f07860e8be340777ad94a31c3c3c9cbb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snapshot-controller@sha256:f8613dc930356e7bf4ae21ac72117daa9fa27655fa886a6b2bf17f22d3615f59
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snapshot-controller@sha256:521754d36818eb155be835bb4702990cfa6f2c988cdbc689b0d96fb55d5429c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snapshot-controller@sha256:2699cdbce786767b00ae719860f87eeeba79de52569b3d0618ae2da9631bd2d6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snapshot-controller@sha256:964249dd5e20de695e016cfe5cde4286e055807c14526076388219c0419c7b38
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snapshot-controller@sha256:f2abd42c323b318e9a074c04fecbadecf9b57e847c0be20a515060ebd61d0ea1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snapshot-controller@sha256:113956856067e0721390317c1e3d80dc3061556f7e6802d506f8c6aa80160539
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snapshot-controller@sha256:42bb222fb828bf20781df7c717c293c00e86e093fe5cc8deb9fc2d988ea18a17
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snapshot-controller@sha256:7f44f3212bcaf471327e7f9405b84800e042889c9311553c2dde8a562de6dc04
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snapshot-controller@sha256:299f50eaaa6b58ccae328696ef60e33d22f8390b6c28bfabe53997c455548cb0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snapshot-controller@sha256:e6619236da17d7ce4986c3b54a89062a000db754f5d7a01428a30543345559b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snapshot-controller@sha256:6fe3c64fc5e42686cf9b39794beaf0d3fa714acad7d2c04ee4c8f856bc715b62