Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.6-debian-fips-dev, 1.6-debian13-fips-dev, 1.6-fips-dev, 1.6.6-debian-fips-dev, 1.6.6-debian13-fips-dev, 1.6.6-fips-dev

Index digest:

sha256:be0c552ca636dffd7f344998d4504e85dd687aeffef52ab77273f56db8f7cf52

Manifest digest:

sha256:46a3248dae3bdcb952b9ed0a1f9f5e8e3d3f600f8f9b42b8dd133f33b7441e0d

Size

56.49 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1.6-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1.6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:df2b2756f88d9ff8a7ad7bde2ac74d5caa2e1585c3dc8bf19d6cd39bb67b55dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:bdbffcdc58cdf9ca51b75be1c6203e7762d645fd93e58636c4c97751acf8e18a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:d958e26753cb9d0d6090d77e80a181009aa2d0e43e49db3f5da830dfe2880663
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:1dc8a0fe7dc17ff69d077915f339e760553dffa6a9f7e50600f63d1d0ad218b0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:8abbced775255f754d902b799147f341573659d79526fece0ebcf23c8bee3ba1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:52f5e5cff0693beb7076245b4dbc82ffe1beb6704fc41570681bbcfc26cc4383
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:f4375105466fb6667bd787ac72d1208e57ef7fff9c3ddfbd4ac66dac92f4931b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:01caeeeaed6482bbdbd1967eddd54c399d1fe163a9b7fa85ffe040593eba9110
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:c495db88767ac0a1096d1e811e9259fe65b0faacdb59e5e7065315cb59c3d16a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:ec6a623c7a802476b23f2fcb301766d24f3d4b078098819864b10d4ff18c7091
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:9464220567b06f731f4ca1c040c98e17a566f17fa53b909ec487e506d6966e47
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:04fc0ce9985b6c84c6d28eb21c1889d29e07488c32971cf94fc2e09b8f6443b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:7ef69025e37cdfd6033f8e76a10d33838143258c7e18a0ba628d26df7bbdbb13
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:ac438b401e336e537ae0e908be055630c843124acb6330bd84f621570a8da383
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:9e75ab2fa37c46e716fbad48e6d997b2a06f97241aa78d5151e7835f7c9e6820
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:0a08f8f65d2235243c279e1fec9f9e4fe0c04f4fb7c410471b471f5c41ce17ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:f5d3680466882d08dfa942aced8b59f44e5a18c08b3fbc8bb47b97b04732f775