Sign inSign up
Virt Operator

dhi.io/virt-operator

Virt Operator 1.7.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.4-debian-dev, 1.7.4-debian13-dev, 1.7.4-dev

Index digest:

sha256:84ebafee9d02898259de31bd4029286d5b9e91e71db653e3b67af7d45ba20b3e

Manifest digest:

sha256:65929b2642adf2b918d1cfaf3351240637a8554d81e045638b37f7792d089190

Size

54.67 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-operator:1.7-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-operator:1.7-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-operator@sha256:e2412b8677bb85660cfcaadfb7477cfa55d784c2e001ce341ef1b88f65d92e02
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-operator@sha256:13aa3818863c113c1f8a0b3cf2516e20684b4ac1c48d5f2489b075b5a2520708
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-operator@sha256:e11e0d42e27f875657173a5fd6d79834c480cd1b5d2d95939cc0762d17ec9224
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-operator@sha256:bdbdd594c51679146e6804ff3970918cbaa176e37acd0ebaa634b69dca2d934f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-operator@sha256:9a89b1f2316d27cc6fd4653c1fca7580a2adfae0f813716d9f85e33358f02598
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-operator@sha256:cf01feb9d1c44e771878af70fd65aa864922380d93083fad5984a1b40360fcce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-operator@sha256:5294404cff8aeb6ef09e07063411a2408bedd3a0930a8fb6cb6bb19a662aa17a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-operator@sha256:1d7d21f5fce19ecf26c1809fc8a49f092e41b4789f4824f481ec9c7ad87e253f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-operator@sha256:3c6ccab9b2ee77f1e6c5fae59533ae29be7679ecf0e6d7d7e7c90e5467d0e995
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-operator@sha256:a3022f7a436a1557d2555560e743900b9699265bd4a487522c583025ecb89abe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-operator@sha256:861dc0a5ded973a8318fc1bf73aee570c8e84b47df5f8105c4457463d6e6a5a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-operator@sha256:5fa5e84e194018032eac5f68ef202dacac4cd64aa44682c6d9612c412115b66c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-operator@sha256:c35f51a051abd3d6eaa5f344bebb70bcfb15e7a505feda88095d787b33581674
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-operator@sha256:be89a86b6fb7e6df34d1949d779047f91af93ad141579a6663845de2f097682d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-operator@sha256:08c0814e8649757a35a4267e8ee7cf701ed8b89f381ca3a692c75c9bee05a295