Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.6-debian-fips-dev, 1.6-debian13-fips-dev, 1.6-fips-dev, 1.6.6-debian-fips-dev, 1.6.6-debian13-fips-dev, 1.6.6-fips-dev

Index digest:

sha256:7ec8bee36a78da2b1b355958c3b2b1af9f63ee7422c37b593c8099b49479a8f7

Manifest digest:

sha256:c619d0904e26bae6f896dc83538447052c69a0a803deec5664c5a49e75c31f8b

Size

56.44 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1.6-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1.6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:5fe504f28a301b2a849da2f8f8ceee30c4b4172107eda1320ee5d843d065d645
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:711bc26d5dadfb2ab7901b4badc5db96fbc77280fe691a2dd7a0855a73b073b1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:9791d2d1ef818703e2e0cc1ecdebf39f1bb44fed38fd553d39275f8ae9715270
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:daa0137a708cbde38f7ed2ce57bc471bee0a2c6d274dffd4dbed9d0c166eb1e2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:3f095b945f92eed85620e8063bef0c15cac1054838ec1ef34cfcd1c41f6850df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:7b408717f29190b15da0e1b385591a37fd7b70b809c40013b5e20965b550a4f8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:e88ccd41fb69b07dedac7b78a318f20d4142140ce97180b6d2aa45f03fcb5b66
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:764e1f802f2951411cb4557ead2baac2e4cdaf6d917ce929644a20377039984b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:9875dedd4e64057d35d42ef6053f86f6583b84ea7a1cd5d6bce1b01f896a998a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:41da812fbd3243160a3c4db5fc137bd5c4f9b5df8fc9e05e00892cf95fe263d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:f90ef104645b8ef74d183e64d03af23639f25d98da86469c99ebf36130c7683a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:e6fa37b058d5132c004d75d0861e70f5198fd081b104a9070a923a17dab41a2e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:42564120953f5234cdc002ab0f6b29fe88ca4012d91ff48b21df41253a13b238
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:90829096549ac7ccad8546a75dfe587ce7ff736c73133368fa4a9947c7e3ed5d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:e9562f50850d2cade5ea810bc9a3dfbf5234ecdc40e5467cabf0b98b8be89f22
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:ed1d5357748d538d5be40bcda2f89a5b7ea692fd5e95a124a925783d5756a1fb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:b9a5c060a4c7510f86b99967a4b22f654973b4fc6a1da6c8f6e1820f7d6f7125