Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.9, 1.14.9-debian, 1.14.9-debian13

Index digest:

sha256:6079d106f4904a4224f2436820950e94146e71bb9be36b72a4d3b54f204d76f4

Manifest digest:

sha256:e038f22d20f828ae309cc6fae184977218399cb81161067a3be094e25f14d957

Size

59.79 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:ca3f19a7936ab58ebe24fd5d2427f4cdcb88fb2a4d214a9020aa95d1e5c5d4e8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:85df4dd0506cc88e46fd63b1f2b0dfebf360729756b14f9571167e0848920627
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:73453ba72977e50c07807477b0a77db8bbcd3539e808b9f1ebd3f0f7973b1197
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:7a38cb74742e71f7b32fdc01a1f82144be92d47aea125c9a9333818c2816dfb5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:aa376dd92bff9390e6921d8722beaf71b6e79b036d6beff4132f487c09410bb5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:422311fd4c7f446f2efdc5fef6df867f1e30c592b2d42677a4cbfb1d6540eb84
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:cc1fdbd8cb24252b12fd87105c49fdbe782ff59c614682b3b111fafe6d361290
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:e24a78da5f56b01338a2f71428f254fd4d90cc79083aaaefe3166f5b5296c54d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:f86411206f7529dfc3f8cbdba83ec482557f1b862d50b484e963b703c7aaa506
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:fd57ba892fa2887d7731f4cd8c4c19aa86cc92a05ad25ad8aae0fb375d8bb167
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:ef8369994df6a4166a027f9511952a099f491a2ec4f6334f6371418895232c52
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:998b8659739e349f6e89efc1a01a2915200ca4fd5b316c2a48f3e2f1e7ac246e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:09f4040fdce942899db5fef277726d0525cde5d1a1d067cbfb8aab271e889ff2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:304dfd3c76fab3e1fe2492a9b795dd2d54188a0a9e3acea7578550be410bd102
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:795a58a1ec9d23566a4a6942c1d797e312bd06767f28dd53db0a7a7f00aaafa0