Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.15.x

CIS
linux/amd64
debian 13
Tags:

1.15, 1.15-debian, 1.15-debian13, 1.15.9, 1.15.9-debian, 1.15.9-debian13

Index digest:

sha256:adb94414df487f8ffb1b76f9e45d9aa63a65a3b502561cc7571808ced9ab9161

Manifest digest:

sha256:fa4c323224839a2fe0196d10e155d71fefeb66349d1aee40a709a954d78616be

Size

59.54 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.15

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.15 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:419331874ff96f5229dbe189164462e992c6cceef7463043e6460bd959e52ca1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:b40ffd385dc27b887c3e06aca86356c8cf063264942a840bdb8873acb7b17eac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:da0df5a09dd8f54aef5a1eac5956174a7416f3d928ba30ec436030eddcf2af03
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:bb7c22b08539f07a60123661766d2ad8e511b99e8d52e6bf3fb427254e3eb588
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:ed30d33779f262aee4de61278033adcef79e97db683ecda54b8a785627af96f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:9cfb464e4e617c59cfa74879e25d339907d59deb40880b7d3ecf153b9540a554
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:f3baeb3f81499279af3eba182aec04f430ced605e31d274f68efa34a3f95648c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:9800d76e2d92664944235ecf9c40611ece6536588c4ae4a4180e3657779f8e5a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:59d663b73ea5ae062c504d95de75b9db4a969a0a255229bfa14d9d6cb2947fad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:74acfa8c3cac5a02e974e1d478bfdeb7ce213865b3c820ed3fecaea6882cb2f2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:f5e227f8708e21b350b22cbc686fdf9acfdcefdf0167d4ab0927534f2a9a54c5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:e4dc4b7ef2027b8fdde069fab9ff42b0eec525ea19f5ac5f1178ce3e50e930b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:772b77a2c95acfb1da89eed868591615ef1b886474a212f093e70638f2f79956
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:6d4f6fa01f24dfe6df66dc34536e9a07d01d21fc9e1de22165aa3ea2206aea5c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:2911e12577cfe2a8b172612aae4367c101f1328aa5e4f681130ee8cb45d139d1