Sign inSign up
Vertical Pod Autoscaler Updater

dhi.io/vpa-updater

Vertical Pod Autoscaler Updater 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.0-debian-fips-dev, 1.8.0-debian13-fips-dev, 1.8.0-fips-dev

Index digest:

sha256:73daf4095ebf142aee471f04c1ac1371619abda3f76989ecbdc8a2b01ff4970d

Manifest digest:

sha256:323e97c7299cd8da9ef9024286c6f6ce2e36eff6e1a7211afc2890f298fea162

Size

42.25 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vpa-updater:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vpa-updater:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vpa-updater@sha256:8b80aade442bcbda0aa8ac27583d96f4db8b67c215b5490d9909794d3bc88903
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vpa-updater@sha256:9c69c5734f9f604d9f92a6a2842fe0d80a47e50386c36ae13c81d7da8270ec88
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vpa-updater@sha256:37b729114180c516ab1de548d89263b67e91235a554817be58be3bc27a876758
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vpa-updater@sha256:adce049c0a740637ca4ee710e3436647ecb1b273e5a08901790e329c432d3848
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vpa-updater@sha256:448828464982511e62415683cf945a10106ba9f18aac4038bab67a2e7705d46a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vpa-updater@sha256:2d79d535250f13c04e9198900b8307be14ba62331958f37e14331b84430ca74f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vpa-updater@sha256:fcda5a44aac3e797ff987e2da5e49a6b00f87c219447e0e1414ee6ea271503ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vpa-updater@sha256:89f2ae7a083f91f8819d23392d6df3388e91de623455a40e25ca69a9f2cfe0c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vpa-updater@sha256:238a486ec19e2fd31b93db0a6c69dcbae3266442c7a41176860a48ff274f4226
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vpa-updater@sha256:8ae476046b20e433ee40f09bb1e03908349959cb8d1fb08ca964e56ca088fd64
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vpa-updater@sha256:a3710944829583a98cc3ea3cdc223e57b858876ed81077e696450f05749fbe5d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vpa-updater@sha256:1f99a63e2756c8138f0ed3370900290113af8f0b2c1cfdd3ce80c32cd05c63ae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vpa-updater@sha256:b9516d22498a3f59ac19c3e77376037e321ae450f71ad81a8ed3da139fa6116f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vpa-updater@sha256:c586f22976a45ae72f13e77ee2be399d7959633c0b83cb5b8a749764d752c15c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vpa-updater@sha256:bdb1f1864fbff2ff5c4e96ee56e2da64be9d9eac5582725a03de3d9c27c1625e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vpa-updater@sha256:3d39ae60b593e7e6860d6439dfc773fe5f12c68150d998611c4d1dc2eef2ca1d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vpa-updater@sha256:bd7af3cc6aac05612388ff7329af8c8c547e5d8ab20fdfb59268a6156fdaf420