dhi.io/victoriametrics-vmauth
1, 1-debian, 1-debian13, 1.152, 1.152-debian, 1.152-debian13, 1.152.0, 1.152.0-debian, 1.152.0-debian13
sha256:a88d1208cd609abbf2d73526f8b0afdb1943118bc1af22341e80240badd3f802
Manifest digest:sha256:6c5af37684de220d1c668a5312fbc00991fef5bbe66a764b70569e92d97230d7
Size
4.06 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/victoriametrics-vmauth:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/victoriametrics-vmauth:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/victoriametrics-vmauth@sha256:2532e7031d75e1699a8c36a62fb2419ef8028c0ac9491b2cd0e91df214928ca0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/victoriametrics-vmauth@sha256:d391739378d4a5efba7b949aa6f93bbafa590ac28418491133b6c632e2d6d9cc |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/victoriametrics-vmauth@sha256:d4c28bb62771da885c80af1f7b88df401657307028fc0306206a691a14104dc2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/victoriametrics-vmauth@sha256:6249a30524c71c9a3f719dc4411ddaeda805080f87a1a6eb23a9a2dbe8440499 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/victoriametrics-vmauth@sha256:45a7943f2c95332286b0b2b98227d6c74304abf2e90a8312f46f07bdc833645f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/victoriametrics-vmauth@sha256:32bbd96a992bbb60226b25eb8ea763908304e9b826aee36e442ba4eb6832deed |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/victoriametrics-vmauth@sha256:565e812ca59c27c9cff6d1f9ad1f639c304bfff3cfc416127ea4299f267ba146 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/victoriametrics-vmauth@sha256:c63136cc76cdae3ed4f4d50d8104fc20d49e717e356b24d482bc7e3a9740f8b4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/victoriametrics-vmauth@sha256:d91fe089a2beaeb73b7862fc914ea17ed5548b5b951dd057e72e206e8e667467 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/victoriametrics-vmauth@sha256:627363d49e3f8c4b7507d1412dc4835321a3725361e59fe1db5aa07d82c44c4b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/victoriametrics-vmauth@sha256:0c1dfe6587af8295bed87cd57d43c3b3a6d15dc933adb4ab2ede0b9947255cba |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/victoriametrics-vmauth@sha256:2d7a6af6d73cfc0ac65f85f3823598c59d3124eb9f231c90c37e87b5ea6a0696 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/victoriametrics-vmauth@sha256:56db606e0a11173441149623ec7a44fe98e7d8f7bbfaf5ec0e3d3941cefc9f0c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/victoriametrics-vmauth@sha256:1b38c2b75bba7c22581859e56b59c90ee85c3a64fa178427fa572313c91e6551 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/victoriametrics-vmauth@sha256:6e50d5a84933193447c0ca42afb2d2e62edeb3ae6472431e330174c85ed6d399 |