Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.14-debian-dev, 1.14-debian13-dev, 1.14-dev, 1.14.9-debian-dev, 1.14.9-debian13-dev, 1.14.9-dev

Index digest:

sha256:93c6341ca54d04a6b72f37ed76cdfc5ec00e8bf471ed1903c727d51c4e882286

Manifest digest:

sha256:c27985b87c8e6b1e12904a6856d0b8aaabef0e42e0b17b8bba894791c0972c32

Size

104.26 MB

Last pushed

22 hours ago

Vulnerabilities

2
4
0
2
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:06848da5c53e0d29360bd132575888fa61ff3a5634f8c9c227d05145d1921b0b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:7b64116e25050babc7f32f9745324e85789ae0b46a80bafebdb4959094a16a31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:5abe1753190ae54f2b2a0278b1b02072cf65c3ad5d09137fe982909cf21fd910
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:4b4b548b5abbe979e11010f6b8955b80e7e33a82e7b6161610223ef01c324e34
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:ade1447517896c2578b858bcc8fee9c1df9052f296561148209e1e032fc14054
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:8de5e8df433b4b1938eefc9518ba8af4791247b8ebc81bbbdaef214afd1151bd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:a56ec0e6da686c0c2a740f199a61eb6d3322a3e51c2fba765fdcb6784765f6f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:a2a47fcbae16aea8d39f5986afbedd41f0a188741b6b5bcdd422607a82197fc1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:f2a6cea7ed885d18d80ae2f1189933f3686f23f6398ebe03c76fe83d69b26600
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:339a70593380305f909e3c90d636558979595e82c1663fe39ee72ec44caa6733
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:6b84747f8af99ae86f8fb23d3287f1eb7af40ededb68a9cf60fa961268e099c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:8d9dcc5263bbe40d4c7b1b4cb943fbcc21676e3c0c3040cd9f7751270a3e6472
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:b1a47f435b021e8951edbc7f13532cdfaf87e4b1af5ac7781b2a8d1dc63a9926
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:a5b13a834c8fc53b7a474881d4b0e8c443bf1c624c5c6f5a5fdb0ec371f7d8dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:572e1d643baa8704b6b470703534fd6dbc632d2a0a482e0efd6e049d29bee8f7