Sign inSign up
Virt Operator

dhi.io/virt-operator

Virt Operator 1.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.6-debian-fips-dev, 1.6-debian13-fips-dev, 1.6-fips-dev, 1.6.6-debian-fips-dev, 1.6.6-debian13-fips-dev, 1.6.6-fips-dev

Index digest:

sha256:1fc81aa0cbc976bc35692247e159598da0fa7a09e983930680f52248a6be092d

Manifest digest:

sha256:c0a63e9e603f9928760ac3191fde1d9556c1a36b2a3142666a194c7342eb2c5c

Size

55.98 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
3
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-operator:1.6-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-operator:1.6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-operator@sha256:3628425e6a65ade388577ea59e65aec1cd1f8f23004131fa1c09506902e5cdd8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-operator@sha256:8ec7036e96ac4c96aa8b7c9aaf271c66307758a07408b98247643f747e2e4256
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-operator@sha256:584d3e09b93ba70432b3259612dd6861a42bb19b8ec9bd3d9c1cf29a014a127e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-operator@sha256:ca6a70c1dec47b127a10aab93a9e0bdae91acee7f5e6ce2848a78c59a3012898
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-operator@sha256:9585030d9a4ae71e7855dde3acf5ab38ddbad86711dde43078d6e995aea69822
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-operator@sha256:b20d47cd27397cfcbd30162730c7ddc25dc66aa677e21314a29dd3bd4e3f4b36
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-operator@sha256:bcaaa9a858fef5c8edd0c4ed1e390bd1c9e9f77853d214211d507f4ff4587310
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-operator@sha256:35512e538a54f828c460aa205d890978fd294c892c64643e10897e2a74cec3c2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-operator@sha256:f9a0653643beb3fb9e8f3ac4d00acfeaa5cf1695c749bd836ad3560a46c12f05
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-operator@sha256:8f88d4db311b6ab28ad4ee23d74560ea6313ef6b34b048b0f4693b7e64dc1343
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-operator@sha256:228ceae6bfb5dbb6795eb0fc6aac306b64d862b4e1f80199f7dd71503b2a75ea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-operator@sha256:d2efbc0d6d4f7554aace3e65cfc044426b407db423bb1be018fd682d335c00a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-operator@sha256:4206d8acab94879eb50d0de065fbda035b810837808f3212e70642f9827edb98
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-operator@sha256:66e90753ef6455247ce2bc60a96cc7574735b4b0ff36207de80fd8f3723e60b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-operator@sha256:c9293c2c5ce301555585d76a2ee73b6ea8b8b66382e5cbae365719141d72d3bf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-operator@sha256:6663a2478f60c875a0a4d9ac34ca31d20d8bcd8f1ca841754ab195ddf3d5e21c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-operator@sha256:266dafba88ad053a517782917e7db7a1a3f7933ad41f800a1927b11bd4a61d55