dhi.io/virt-operator
1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.4-debian-fips-dev, 1.7.4-debian13-fips-dev, 1.7.4-fips-dev
sha256:462f578beb40b59cfc095267ef40a6fb03717084da1d975e3f957db2d5acb108
Manifest digest:sha256:25d8a0b477b1f5dbb4c60da94a80e5f4e42570ab1212d5dbc9c1ae9dcdaaca37
Size
55.42 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-operator:1.7-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-operator:1.7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-operator@sha256:ddafe8651e7f06aa3995557e12ed62945636fa96b474b08ccacdaaef5187daa8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-operator@sha256:ebd0deec8a8be41ea0ba7ef648bec5c80b5764a0a27c701fdad1f1c18da0affd |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-operator@sha256:645a26cc0216494de99849cc38d6e49aa49afebc878594071398a404fa51528f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-operator@sha256:b5e9df9251ec5ef4aac3847de395b991ceae380beb3cab071960455eb9e21e0f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-operator@sha256:cbb532099eeff39c9514da644ba9e936234d354dd60724cdb4c9c06b757eb222 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-operator@sha256:e3f5bc56521183d756ae30a9b0f77131cf3d75e3feab05498f6cc0cdd58aa2bd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-operator@sha256:a83b63373bb818e9cf14095b2b570cfc235bb2a8b12ac471e70ee166a3dc86aa |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-operator@sha256:a1b16eb99d4ac67569c8636c625f9114103e57374da07cf631ad7336c53015a3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-operator@sha256:2b82979e171bec5ba4628fdaba5c2b6e4bc7c2dec6cfbe9b1831e6b5eec3b17a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-operator@sha256:a85aee216adb6ee9ca220a963db713526aaa484fd04019aa0d33ac95430a47bd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-operator@sha256:9b4da6a7ec61684aeeb115c9fe2b83fd8adb262bc8c6c452d71fe620fdba021c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-operator@sha256:88aaa4e204b536a3bec3269f4fa9ef5c59df4e1213df783100885f2e0244f726 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-operator@sha256:95ec2b0dbe94ab6bfc01c72d01773913d32fd6dc4176905ae90ec39f020c0ca1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-operator@sha256:af02df4082fc35817f14cb6cd8272451b063278af3e3de77e7b9a3df48dd545b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-operator@sha256:5b58906127c79ca200403ffe5471897dcca6bb90354544d626b6903ec1825cae |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-operator@sha256:03ac1c146f4337844c4c76e616c5a305228bd5ab0c9ce1c25cadf988ac91e560 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-operator@sha256:538d3c6536b49da43e0bdcf64d07ecbb84f71fa283491fc210502739b5ff3f62 |