Sign inSign up
wait-for-it

dhi.io/wait-for-it

wait-for-it (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.20200822-debian-fips-dev, 0.20200822-debian13-fips-dev, 0.20200822-fips-dev

Index digest:

sha256:6e951a90dd60e0d577ed0f72946bbdef989b9e344a03f60e92669b09c00fca7d

Manifest digest:

sha256:049915974d2e5447990d86874cda83339d2ed273f65d5a944e02e5b6f2c1713b

Size

24.54 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wait-for-it:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wait-for-it:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wait-for-it@sha256:eecd0be07773491626e4fdbfd2b06ea22b7c2f5adc6423b6b457e932c6f405c4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wait-for-it@sha256:6a74b38334ff54719095b47303505facf754f57cda8eaf53620c2255cda44289
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wait-for-it@sha256:5acc65c0bf231e639bf29fa32532556ce4ab83c331e5dc2ee8bf29b73c434270
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wait-for-it@sha256:a4013b23e12ac3848839e925ccb4b2cf668939a3dda324681a17139c5eb2aeba
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wait-for-it@sha256:1633cc052541b84052ace00ed76f2c1c1f3afd210cdf8763905a696034fca3d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wait-for-it@sha256:9a3ec700e16e604fbc9a3bbdabd7fddebc8128292ccc99a212567cc87a578c01
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wait-for-it@sha256:73ce556b5669149fd555afd5ace6d7e1b6b833f3ec54c18116adb0869b122bc7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wait-for-it@sha256:64761555a84dcc347d0dc92f04e1352a138137535c4f9f4b1027c2239759dc00
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wait-for-it@sha256:23fb12f6c91df56e421270677b23f64fa44e4f9d76f0e2a70210b98d34cc5ab4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wait-for-it@sha256:2c585cfffeaa0cca34e408b87c72b7f6a681bac50d1840fb26cf8f726fffc98d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wait-for-it@sha256:992e682a9f5457e078c48ba373c8f09e3255c6d35ebffa5adf63067f296a9fce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wait-for-it@sha256:79bb0358e110cc6627e3e3c1ba10a5b25f375b3b3cd6cc0f3df3f9a10a7d13cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wait-for-it@sha256:2d68503adb2c4d862b23803ea9edef8f92bf07a06ff65c34014bc67f829f85a1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wait-for-it@sha256:34778f4dcfdd6c3b6160c95850ea794d81f779081556daaad443905f71a2abd8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wait-for-it@sha256:d2982253203b524ef074ca6a99920be5da22c85d4e2428eb900995dfdab8aab4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wait-for-it@sha256:8218324a15950fa5802d5602928387c90f9c3cf49275ed88b77c7b10fda7475e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wait-for-it@sha256:fe5442b1499d977a0c6af51eb4eca4865c63064ee979eb2614b4e5dc3f84157b