Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.9.x (fips, dev)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.9-debian-fips-dev, 1.9-debian13-fips-dev, 1.9-fips-dev, 1.9.0-debian-fips-dev, 1.9.0-debian13-fips-dev, 1.9.0-fips-dev

Index digest:

sha256:70dd9351a820dff9600e1f613f7c90449463466fb58e30c52c9807caaa8662c5

Manifest digest:

sha256:0fc3212b017df6b333e2ba11609d24f29d4120efd11cd4ba2de90e25a06c308f

Size

57.61 MB

Last pushed

4 hours ago

Vulnerabilities

0
2
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:17ee5a4187dc49ac5dfe7274b2edb143a07e6753ac20bab381e0b1b9abd37f40
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:14ad1d5941b0ae85b6b0c434e540881e87068593b7df2b77a85dc6ac57720783
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:47c1f43e697df7cd6ba8ea65a182d6a120fec4f85c5ac2fbe96ca17c59ef2f26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:15ea3d805040c4e761d4ab0fc8a19126066704388e0017027ef7d9d81e9cc2d9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:e9f3272b959271edc10d4a405f8d11b2fd961d81ba63ab1d366f97124709716a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:ab11988dd3cb19b4ead90e42b172c61d1f23de7bddca15e4c42f343c77012206
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:75d99427449f64258811f2b8a8e6ab5e249238e39ff4854d0b036fce4ac270a8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:6c6d99cc6a4e359db0ef83c6eb8c1e872b01529742051e6f4ab9dcfdafe1f912
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:1a99b9b0ca60b5fe351031363740f075f1d3897e62632670fb5867afbb04085b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:48edf7425f1bf54458c8177a161d6b1b440f185e2d985635bc1dc8ada7630a40
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:c1c92572d78b4ef9b5bbbcf49b1da0c7bdeda9189f9401949f840a42426e8c52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:cf4f0103ab8c8cf47ee5970acd67cdf89fa841b765d09bc945a3dee469171e28
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:16bb39a0dece8b94bc11abbc6210dfe81eb7275d1e6dd264f795ab1d3e4a8e79
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:1144674ececa344a83c417bd843293121ae41d2f2fde3058722bc3ecc0a22173
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:f8fbd16f32a1d720be597de80f35b310bbce27960c3de799a2bb6cddb5221a07
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:743eb1c43dab1c3f7731455ed0979bbe905e36d14784a94261915cc23e8155b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:7920e5106a86722e2b1395d6eb5f34df87f39a3e2b2a5e80b3bf59eae1a25b36