Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.14-debian-dev, 1.14-debian13-dev, 1.14-dev, 1.14.9-debian-dev, 1.14.9-debian13-dev, 1.14.9-dev

Index digest:

sha256:01ee4cb2dd5ee8fa39dcf0d3fe837cc256a6d5ef122c0222cb6254231ba08035

Manifest digest:

sha256:28364e17a7cd8c713c741d81213dcbf6dbfa451ff9b01a4b97c720dcf6fb6cb7

Size

104.28 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:09b3e781f74922a3fbf024f3d4d0d9144fd2084ce9f0ef70be5cdb4aecee0c4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:d22d2b80f626c9a04bca0e950d46afff5f8ab306a071477eaab821302c2c6c7d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:135030f1c5c3adb8bc9a6f06c269fc869f80a0f4cb7c91c7d78596de7e95a083
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:9a05d6f20c0191d6c0a3043730809f848be7a1a33e61b35884a7377768e9e289
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:bfee8a1fcee91c9dcbb2c2a6d30499b35b4c109a590ae495af1e0b324752b8e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:eca3281e10606999e9459aef610d26132d9e47de4bb1a1996cd2e74f0db6df7e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:a526efa38a42cae5b915ee8f1d8f8820d62673b7a9b843616f15bcd4ce491513
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:191e0f753ebd10e848326668adef59ef492743d7559eaa6930aa099df7d5a492
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:f2d11b8dcd503b58abf70814a70dcbcd0112f356b7a62b2fcadd343097994a4f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:edf6539fad3b9d60edf47cc5a15d5dfcc58480a0924d04c22a22742e72a6b6ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:793ef7df264694cd729af039ae394a6cac2d729f7fb597c4c0e1247b90f46716
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:4e32c11a18f6fecce2bea4bffe95eeeae1b23848d5d44c533d484f9185ece611
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:fee7b6e149ecff2db6c94cc32e3efc1c772fd2842cb35268e5acec528a42d79e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:3e0053ced45226f8decb6c0dfe6843a5c8df44ee440bd632ed30d09a6b7a5c46
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:a4b552df66a7375e0ae0025d768c20383ceb0a8e1aba25899e3c7f7f247192e6