Sign inSign up
Virt Operator

dhi.io/virt-operator

Virt Operator 1.7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.4-debian-fips-dev, 1.7.4-debian13-fips-dev, 1.7.4-fips-dev

Index digest:

sha256:462f578beb40b59cfc095267ef40a6fb03717084da1d975e3f957db2d5acb108

Manifest digest:

sha256:25d8a0b477b1f5dbb4c60da94a80e5f4e42570ab1212d5dbc9c1ae9dcdaaca37

Size

55.42 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-operator:1.7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-operator:1.7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-operator@sha256:ddafe8651e7f06aa3995557e12ed62945636fa96b474b08ccacdaaef5187daa8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-operator@sha256:ebd0deec8a8be41ea0ba7ef648bec5c80b5764a0a27c701fdad1f1c18da0affd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-operator@sha256:645a26cc0216494de99849cc38d6e49aa49afebc878594071398a404fa51528f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-operator@sha256:b5e9df9251ec5ef4aac3847de395b991ceae380beb3cab071960455eb9e21e0f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-operator@sha256:cbb532099eeff39c9514da644ba9e936234d354dd60724cdb4c9c06b757eb222
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-operator@sha256:e3f5bc56521183d756ae30a9b0f77131cf3d75e3feab05498f6cc0cdd58aa2bd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-operator@sha256:a83b63373bb818e9cf14095b2b570cfc235bb2a8b12ac471e70ee166a3dc86aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-operator@sha256:a1b16eb99d4ac67569c8636c625f9114103e57374da07cf631ad7336c53015a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-operator@sha256:2b82979e171bec5ba4628fdaba5c2b6e4bc7c2dec6cfbe9b1831e6b5eec3b17a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-operator@sha256:a85aee216adb6ee9ca220a963db713526aaa484fd04019aa0d33ac95430a47bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-operator@sha256:9b4da6a7ec61684aeeb115c9fe2b83fd8adb262bc8c6c452d71fe620fdba021c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-operator@sha256:88aaa4e204b536a3bec3269f4fa9ef5c59df4e1213df783100885f2e0244f726
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-operator@sha256:95ec2b0dbe94ab6bfc01c72d01773913d32fd6dc4176905ae90ec39f020c0ca1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-operator@sha256:af02df4082fc35817f14cb6cd8272451b063278af3e3de77e7b9a3df48dd545b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-operator@sha256:5b58906127c79ca200403ffe5471897dcca6bb90354544d626b6903ec1825cae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-operator@sha256:03ac1c146f4337844c4c76e616c5a305228bd5ab0c9ce1c25cadf988ac91e560
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-operator@sha256:538d3c6536b49da43e0bdcf64d07ecbb84f71fa283491fc210502739b5ff3f62