Sign inSign up
Apache Superset

dhi.io/superset

Apache Superset 6.x

CIS
linux/amd64
debian 13
Tags:

6, 6-debian, 6-debian13, 6.1, 6.1-debian, 6.1-debian13, 6.1.0, 6.1.0-debian, 6.1.0-debian13

Index digest:

sha256:329d724ce5ab9b1cf29efa163fbb53997f4309f67bf0a998d0c93bf7513ecb54

Manifest digest:

sha256:a3b44514e8393b6e2fb0da5567707b87e038fceab9d49561c797b98df7eb883b

Size

298.19 MB

Last pushed

12 hours ago

Vulnerabilities

0
3
6
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/superset:6

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/superset:6 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/superset@sha256:02af054031afd75b0b6aa41638a3c0a636b82cc00f2135eacf0c2e21ee38e640
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/superset@sha256:c22c0592b10839a2240eff229059b676cd66c95f696ace53ea32a921f9bbd8b3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/superset@sha256:3835e4a8a0e08cfd743c04b9d29adf78869f9a1f8af8f186fb7b83a5b5ec92d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/superset@sha256:92225b699a9a23bf804e6fa4d74b5bb85ce09e3e8250dc2091e7bd0dbc6e6ba8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/superset@sha256:8f783ae5b9e169196eea675914201996e8e439946e1514d8af2538f12961afa0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/superset@sha256:69b2257f64b619c858270f71c6c904c9ed2f43aad37c425a076f30d53393d55d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/superset@sha256:6d330cd4eb58adece96cea3f777e9dd82b3baa120a6255b5b036101afb12da0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/superset@sha256:5bdc25cb015a7d462762aea7da0955c37c1ea9afb33ee0792e4f8e9ecc1384a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/superset@sha256:3ce376d18f2b8642eaaa93152f6b7ab57389495363f2de75023ccf15e817c7e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/superset@sha256:f6240cab132a0e0a1248e054f1167928ce094a91203c0c51c32c49c78a2a3ee4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/superset@sha256:c5b0bfc0aeec5b5c42e7432e0e02928a0cd9f0efa5ad5f467f0c3fee2a0560cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/superset@sha256:0a95fecccf7b60b72baae8f435aeb3dbe1ee710a8a62cf2a821a4b47a50c25c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/superset@sha256:4fc8b44e99e5e93cee3d1c6e4b954c13b17a1273fddc1d3b64e0de5bb72e0182
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/superset@sha256:f17c8e218d9df3092fbfcd177c921efea34cde5a649ed3b47c77f6595480f52c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/superset@sha256:1278112365ef05d5c5a1034a04f4e93f5003f22c2e5ba2966a71364bc1b9e01d