Sign inSign up
Vertical Pod Autoscaler Updater

dhi.io/vpa-updater

Vertical Pod Autoscaler Updater 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.0-debian-fips, 1.8.0-debian13-fips, 1.8.0-fips

Index digest:

sha256:7550ec4930c7febb45126d1cceca8da3516b7ef9bbcfd3ec85e236508947ef2f

Manifest digest:

sha256:e49cfbd394ae5a30e629e2dd330f2c90224c95fb37504837e2847344a680dd0b

Size

17.66 MB

Last pushed

7 days ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vpa-updater:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vpa-updater:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vpa-updater@sha256:5ebb2fe50a87677348513142468faf4e61d197b75c944e111827c20e23c32e5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vpa-updater@sha256:9fb5ea7464b62e9910ca44373da11b01476e2f6b8ffa365db0f5b770295b99a1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vpa-updater@sha256:a514339ab30ca755af2c462c9e89ea3e3ab9a66767c231da2bd189687545328f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vpa-updater@sha256:d27b845967b0832b3cd988784e1b8a1925473ddc9f717a7cc92606f0d46f0260
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vpa-updater@sha256:886d2954136dd28492fe267944f5fbd260163f028650810f523e50d1d0280783
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vpa-updater@sha256:9b27d7f95cd28aba949c073e9129dc47ae511c971254736ab157ee2a3232a5f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vpa-updater@sha256:416905bab524ffb0ce3595a5e0ba687a9e0aebd5af7f8cfbcd612aa5887545cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vpa-updater@sha256:bbf0b8607bdb58962b4c2318ff76c54dc49c91761d9405b5ab2d80d941b6a0f2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vpa-updater@sha256:a0e98dcbf627aa69269939d93e80b2c24af113ed61cc4d2d20342852ec773768
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vpa-updater@sha256:336fcd7ff66f9914957195e66a1cd99396f7468983bb58bcd6ac5336bd23488a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vpa-updater@sha256:f48fc2debb50f95874d343b333ca993b66471e7cca7e2e4bd21d4c021841e155
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vpa-updater@sha256:c6050637fe20774ac7bdb8244f441d2597ed8b5fbc85019a9a8b52d2d1bc945b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vpa-updater@sha256:e02d3987d1b9ac10d758361cf5444c56806c6dfbdddfa1e278d7ed860a533b91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vpa-updater@sha256:84f441082367ff125f93fe801e3f541f37f5529a250c0943edd08dfa6695dd83
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vpa-updater@sha256:0c630de90296a38457137daba97d99be91207324fa522a2846a67555b1a4ee3f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vpa-updater@sha256:fb45b57f4b34143b3cde585b815193bdf660b4c3745b02e6053c52254ded095e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vpa-updater@sha256:e51571500a8e3917fbcddb3004f3299aa25ea963d75bccb22885510fabd81e56