Sign inSign up
Tekton CLI

dhi.io/tkn

Tekton CLI 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.46-alpine, 0.46-alpine3.24, 0.46.1-alpine, 0.46.1-alpine3.24

Index digest:

sha256:191e3c466851dd8f42e4362db33720f1c39bc2f22245f3d55bcd8b454ba16def

Manifest digest:

sha256:a8bf5a09a49f136d106d5fbdcc18636c8ad96fbf7b350d5f55900d352e65c9d9

Size

17.77 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tkn:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tkn:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tkn@sha256:4b8694ecbeb06aadea281cbea300a112e30b868812fa965aa933756ad78b8453
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tkn@sha256:2de58a92c25b4745a7cf159dfdef444982880b693df6f58eb5ef1c29678d9e76
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tkn@sha256:f43e846c4eafbf0db21f993168906d02a858d983aa99aea34ac4e799ce766d7f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tkn@sha256:1aaa9578fbd3effdf7e850365101231555c8fb61d90fdac9549cdcf225886c65
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tkn@sha256:03f6a51d95bba7b61264c2985def17dbf5be5c0dfbe7c88e3521cf4223ab17e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tkn@sha256:3d888f4e0430b8fff5a4382956006abad02e3f2363e974bbf4daac17d267f4f0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tkn@sha256:f2c84d9df9bc1b680639a93caae428868abe595a2859c818114b38e17d9be1da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tkn@sha256:aedba7eeabb7647e8b8b924903ef6b5212caaf67c138ef6ba5ab30c2b2adbf72
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tkn@sha256:05310e4df58dca52b30cbeaab6811a9a2a78bcf34f944d65b72a51c55893570f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tkn@sha256:9f5f17e40f7fcc70d4b9af96ed5176087f9653b8f18b314d41494935ddb3b4a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tkn@sha256:6ba2e8b88de5b0d206114a76edeb696d9c93e0ce9c5c8815da23cf99d5d4bb9f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tkn@sha256:6cec7479cfada367b241db8462460e082c4ab7424daa4a6d4e94ec1879582a71
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tkn@sha256:a3d9e962f4ad20f888062c5c2e9d746a0bab48846f0ace2d68e7ee5faa48227a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tkn@sha256:7a0c396f6f4e954803c428f9a749aa5f88b1c362afc621cdde430e3bf687dce7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tkn@sha256:4007aa57cc899bffb0d51deea511a42ef48aab2d91e25259cfc18b612b3a1b69