Sign inSign up
Stargate

dhi.io/stargate

Stargate 2.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.0-debian-fips, 2.0-debian13-fips, 2.0-fips, 2.0.51-debian-fips, 2.0.51-debian13-fips, 2.0.51-fips

Index digest:

sha256:614bfb31a2b608962eb058b9676d4afe10e9f4c3f8e4c43fc964f38226517266

Manifest digest:

sha256:fe3c3faab9bf2c4597c1dd2037b7a888682315ba34d89d60a0643e961ac42b87

Size

343.32 MB

Last pushed

7 hours ago

Vulnerabilities

1
5
3
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/stargate:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/stargate:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/stargate@sha256:bd8c21813bc301b0665ca75e100917b061d2623a56702555c79df82db6aa8223
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/stargate@sha256:081cc3c1043d6966d053d1d51f358cdded0df1cd59948088fbfbff341498338b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/stargate@sha256:e402ecb6b4daac1f49628a9e11de0718c86fa04cbd14603313b3f3f44be5bfd0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/stargate@sha256:73a689baa3a37791d897c29d85554f9410217a4133730df7746611107a804ae8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/stargate@sha256:944c99aa3944d92182109a45741d06fde8b9ca694b139b26810cb76b2d78fa4d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/stargate@sha256:928c67d8d52efb347ea515db73ec4177b26b645bd4985b2eb9810cd7a0d20170
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/stargate@sha256:b7ead81fc44ffb9ab1074a3836986c09858d956602cf1765d93ebd043cbe0542
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/stargate@sha256:928b55f05a35f01a8588b8b8f748afb29382850c037a62d1d76695729e5d90cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/stargate@sha256:0dfb8924c07b01779008fd524a6d1e8266fd5239bf489379e88b77f4140ea34b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/stargate@sha256:2c19871a11d5c2016027845c91b037a169d407369a02a3943612debe159aabe1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/stargate@sha256:6e2964f260292ad234891732af4ec40ccce71e6a60c0ac5328b5483d9630ac4e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/stargate@sha256:54a163d84c1370fc6648d6151a811cc7ed9b7a6ec78e11e54f14ded64c9e1cc9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/stargate@sha256:c280a448bf5c045e18bd1184a9db548bb565745197f06e9e5f574f2f6ccc726b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/stargate@sha256:13a3b60ca4f5e1db6c7c6af94955275d94c3bc0b2e64f688adfb7bf485f17683
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/stargate@sha256:905b900f27fad34a9c216390906d5564cacb67318d2b8237123cca6b206062ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/stargate@sha256:19a61b43dc15b2791c80dd9f3978861166caa9157a9d511d37a0f9836acedccc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/stargate@sha256:d335b346a35594abf894187a2ce2e7a84edda6f016470d3fad53484b0111f425