Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.8.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.8-debian-dev, 1.8-debian13-dev, 1.8-dev, 1.8.4-debian-dev, 1.8.4-debian13-dev, 1.8.4-dev

Index digest:

sha256:c8abf2c78ca1fcef0184165421d4cbd0c43030180e6b05718cde6e6b27ac6b64

Manifest digest:

sha256:cdeb21543c00921a713b00c9d128fd37cd3a61c3f8a70e96272705b86923e602

Size

57.08 MB

Last pushed

19 hours ago

Vulnerabilities

0
2
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1.8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1.8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:2f684d09dd5b4a13db52fd883ee95070dabb1f3cfa0b69822fefe6bf8149682d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:53e87129fa847d1ccf17ee22918214d008c8b19a892266b34ef100aecaceedbc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:1e1a32a6ff3278999178c0c2e571bceb329f2ea94546ad6f13ae01d3328b36bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:571ca4f0e9a81fa31c3820a48ea52600d94e828242f38a88319641a602b4e57a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:465f6ac637474fbf593f9daeeae11db8fc66183a43161cee1be9b1bd1ddb1082
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:c0d174714202fe5d114099c22a1d69f574236f10b742b4b2dfc5d8d99283f71c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:4f27e54639a46a93734b9364c4962786557c670a7977fbfcfdb770a1a0e1b89b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:c93db327796bcd9f78c0b769be48be8a49853f43bc6ca943606f2e64418e113b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:c835589eee8a21d3bee3d01a5fa50e24d4f26780297d09fbd25c403f5e1607c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:1a98c20a0d8412ce2a343c559b5cc294c4a84008578a13667da9c7b04d2afcda
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:e97b74436af51cdcd39ce4350d000bd2b2ffe87ebd548820538855929551669e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:75bec7338db0edd8cc0dd446027015453ef7e0795a90e69754ff4172e54b0caa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:99e5cdedea00042618a785eefeb8c9812d13995e873c9e92f09150dc255ea36e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:c3f1096073fae599a8185e4de05743365be3b3fd2ea6d76e52d2caf932f425bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:eb7769bc9a94029fb41509eed5cbc3efff4e6dd67b15de13d4a9864f00faacac