Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.9, 1.14.9-debian, 1.14.9-debian13

Index digest:

sha256:5318fcc099f83e7dc2556fa57ea178e05ab2f2ad6cf51f44484426b5d1699f2c

Manifest digest:

sha256:3d8de65b9c2c04de7631a4b4f4f83c3de5b89a602127301734c057308730bd7b

Size

59.86 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:e20ece95c9ae7ffe3e4ed9a7f32e8ac2347a33a25617a5d5cfc3bd3d8cc77569
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:d01acc55ba239f0fc6c561d4e145849144a7d2aa0dc1efdbbeef30bcc79b93fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:7fbb59b6c6b4326e969576ac6203d4321ac0a005e5f4dc43bcc95230b8b97f07
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:34a1a0577d66b356cebd9fb24b9c2bade24c8faf65134321cd6beaa1508b2a00
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:001e5c96a68bd698b49d4d62c210437f3b2cebbd53a0f2998eaa7df3148807ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:3987c11337b21b4726abdbe42b509e7de71a73931c2550ea6cb3b80ae0e26997
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:6f6a519d48b7ceba45cdcc8cd6d4e44ed3f3b1fbc96e43ffa0b8359d2c77ee99
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:7711adb62a55b7d273d5829bb8b413a0a3c87a067d174ad804479bedcc574017
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:3ea2d7f68e3eeb7a238124a7f633ba4b42e3eb1db5283b1f358e086dd5f84e91
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:fb7835fed45bc06135fd47c02ab927b32c6e49964dbf10d0decec704cadb2cb3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:bfe08795de2a333d38585a2fcc0795102a8502218957b1f208e7cb477418cd59
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:7129b960e3aa9e51ae91df08fe4ac7ac11c67c592d72812ff27f910c4f430923
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:59463261d8f1967bcb7d8fca61ba6b8244056a0588ed853e9ede282011caf08d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:c74e0e800df2ae84052eaddc209d5b096d29b63d90f2d9cf5f824921ccc5d552
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:7916441cd2325128e41f00126b204ec1107750f72c52808174cd44dadf7ff93f