Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.6-debian-fips-dev, 1.6-debian13-fips-dev, 1.6-fips-dev, 1.6.6-debian-fips-dev, 1.6.6-debian13-fips-dev, 1.6.6-fips-dev

Index digest:

sha256:1f72d1addc8741b6660f9b4f2d2d4905eb8eef5d457f89892802118b3806d841

Manifest digest:

sha256:d26f656a6800084a203f73aafbab36aadb0db5e0240229f68ae40672ed6cbc36

Size

56.49 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1.6-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1.6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:24a3b92470c419b9b13cb6dd8f053e460ecd704ee33dd846adf0c203a16f8301
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:90b54708863965c8b35de579bf4b07f4e93fff8e3b372e5b500dcb77485b1e92
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:3f3664d180cc349da5c3986a186a226e9bc83d96c63b4a4a7e4c94cf8e93ce69
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:2aa74643e323f54801478fdd0f6b83835a08a271b42932c2e09db3489d901d78
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:273b9e380434204b1c32a75dcee4ec1515946140644b055d437ad99b2fd28e88
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:cea15d793a8d3b2d217b3da423f40d162416e70c2cb047e04eddf764e59e0ccf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:7f1ab7ed7a3afefc7668c2b321d45b38e2ec267650623d346c85c3aff9ad398c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:f155aa8a04d5fcca8642716811fd19eb4cff6b6c656cbbb2d007c6c6334b7098
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:db4f38ff5538edafdbff1e3769d0b23525f7392e4a12b276e8fba68cc364c00c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:a8bf947ab875505271dbdb5a97c5c516b9df87833cf8c5c74e465b76be86400b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:ffe30ea9c1d36f0a043f7c71312afdb45be40e2012b94fa617a3af7b298a1752
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:6207b346a3c239f715edfa5277d7b509b1dede9c4ebc319864cc46c680cfabf3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:629d9c9422e81ccf70b7b61ce49705863526bd2e98cade1743b177a8ef3059c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:1a02c02249c0c8336127a7a619dea8815a71dd4e0a171778556c8c15632b8304
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:ead3c0abe3100180a4b546030729891ed1b755f764ae8e21d0c9a7f5bc54bb0b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:f049a0352fdcd90349b89aa578ba99d99fb9f1ce56436d00b4abee4184cf8341
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:722d67622008d0a85218d32c66dbdac7894b42768199ec0d9506f57aed3ddd42