Sign inSign up
Virt Operator

dhi.io/virt-operator

Virt Operator 1.6.x

CIS
linux/amd64
debian 13
Tags:

1.6, 1.6-debian, 1.6-debian13, 1.6.6, 1.6.6-debian, 1.6.6-debian13

Index digest:

sha256:eb4887f0499c1ebfac377c817f5e37342ded294419e499637898d80ee4e2456b

Manifest digest:

sha256:0afbe6eee43aedb91c49d33a1f0837c2e41d8879f9f609bf4a33656da1984bce

Size

16.65 MB

Last pushed

16 days ago

Vulnerabilities

0
0
3
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-operator:1.6

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-operator:1.6 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-operator@sha256:62a3a69267e46f5da3ef34abfbb8d62aa7c4bb1c8ffc50a3e47050f037473b5a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-operator@sha256:5a644e7489c023b3cb77908a00b53d50d98fb78ecf6f97877f07b4d10c93bdcf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-operator@sha256:a951f95d6ccedcb3a57315ed292126b43dcded730ee197abb4cb45849dae8a9a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-operator@sha256:ed7f5fecf1d993346d5aac2779a57795179558ade63a0f8d80377395d1655071
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-operator@sha256:cf0441a247b839a5eba13610ba7286ba333c4ac3222a6c45fb65c7bc735117b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-operator@sha256:dadc8d5b52a7111a85f7533eaf03bf0c697718cc6cbfd71863c7b22c67b6df04
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-operator@sha256:6b55227323198c865b8fc0db97bc636b4e556790f589146d754e461daa8f8872
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-operator@sha256:99cb1835f7a0af21f8e20ace331d623429c8dbb6651c99fdb2f8389347418f10
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-operator@sha256:4eed71ce998dbdac14599865f04f0f931a606a8561481a729b26c6717603f23f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-operator@sha256:43984e61e06c2e53b0d07e9255ac409943c1f8a1ebe28483b1bb1bf75a138d08
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-operator@sha256:64a448cddf18c6b850c3c1ea1c9ab6f51cda000259e1ef0b164f9f35e782adb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-operator@sha256:2dd7f1b758194b47c829484fcf232b122027646fe5b9380c1e85b6c28931f61d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-operator@sha256:859356c8368023f2ed760c0841ef15c79bdfeb6f2505e5688826abacf3dc656f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-operator@sha256:e77143ba0ddff4ab2d5856a57fb597e74ac44806e5f4378d1989d0fa2db4c740
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-operator@sha256:f0acb62e687bf6bfb649d487c8115c291fecb6b8f615a47d706393055e2cf77b