Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.14-debian-dev, 1.14-debian13-dev, 1.14-dev, 1.14.9-debian-dev, 1.14.9-debian13-dev, 1.14.9-dev

Index digest:

sha256:4a93b93de6e17f04797810987f0af9ee763dd7dfdaac0921b94ee8ba2c031cf4

Manifest digest:

sha256:27accf9b28c1ce29c855a77eb3a6e4717a1b7b1ba709ebdd8922dd59baf59a53

Size

104.42 MB

Last pushed

3 hours ago

Vulnerabilities

2
4
0
2
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:4eaaafc61c1a83c92b885a27b2e82fd483ff335ef663ef779284495fabec9551
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:e738579789e9d1a5259a6c1678735df726badb8a7487d958d53099f7237ca9a9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:a3b9e86313f7ca6a20b27ad1693e8de2e364cce5cf281c9284b45c3d6dc2438a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:a22c9d6782f6402a01ef82c61ae0bc2eff9e98fc2bc5fde379fecb6a79c8a709
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:21dd8bc3efc261752c494c3d43a3a3b5f401f9f52346e5dd90d64c4aee791ab2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:f71db023c6bcb6b30ef41485ac3df24ae9c802555e8fbc611b5c8e641b959609
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:7ab418ee1e0e5c99e81c71f1ecbc285e4c4c06fdb68abdb15055046740f6a72b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:447888361dd3be51e5132db6202115757b0e36cf761d1baad505e251a42d69b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:6f67013e0aff8a161e4110f37817b57e1b6677290279e5cf5076477f99b20485
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:577a9ea8af33278ea7d05069211ae380b3ea22f55186f5b26c73e621f2e775d8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:7f630a9d7e4811aed25fa8847cdd7be6ccc87e85a898ebcb7390f26458a4903b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:4f0c974b6f635abbd81cccc20800fa008bb5c4918c8db6adad8bae6075a04ce2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:03b0e7b7eb0642592407b3c89cc9d81a2965f97ac6efd2ff2d12f916e68c4b50
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:e459da565887accf5ca04725777a47b788534d3a6cf3be21b1c2e38c54a76b51
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:1e679da165187f040c0b56ed7fdffc7f10460aff8e47e3faea25704ae1742fbf