Sign inSign up
API Declarative CLI (ADC)

dhi.io/adc

API Declarative CLI 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.30, 0.30-debian, 0.30-debian13, 0.30.5, 0.30.5-debian, 0.30.5-debian13

Index digest:

sha256:751b775a9f610aa37e0158f1e7fb53d77e65e828bf4b2fd02709acbd72410fe6

Manifest digest:

sha256:a0445ca71fea4f4249c7be9713f82ac78bdb71b9d0c5ec7b3ef26b4e0c44ad3b

Size

41.89 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/adc:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/adc:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/adc@sha256:bc00b8e82b7e6e95ced6fffd823ea579ea7a98b23f40a5445e8442c9f81d6708
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/adc@sha256:635662ed8dda3766a166f9f013d57d0cf17d6b79b7af828e7d252e107dce4e0f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/adc@sha256:c50509b90407f795d2c7bb6afd1519eff2e022ede519f8a36d577604db31cc04
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/adc@sha256:e653e87c6bdbc6fbedd9a3b85de4df038db15c28f68e38fcbb9cd15acac6b04c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/adc@sha256:b6db5b2621cdb962142e58821385e08cbdb1aa840c35f934a1a02f3e37d82456
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/adc@sha256:bd119e76a6efba2dd4882472e113418614d701727718ec99fc3e2188179cee07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/adc@sha256:807893af1e4261d62a7374f31624ca8fec8b3d926bbcd8fe9cd194a0aec86a83
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/adc@sha256:b7ae043dd8bb3109b68f604af0007f5ee6490c1028e7003e44b735e8735654eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/adc@sha256:8b007f2bcbed395f9f52d0d0e0ee1fa68d322c1813881f0fcccca63f5e9af4ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/adc@sha256:075cf06477d56dd8956c6e40adcbc7b8169c192614415c25d62a022ba8739ed9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/adc@sha256:9a91d1247175da7bc79b283643f27c731756c15b39c970200bcde45a069cd48f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/adc@sha256:09bbdc0d31695bab60ea0d58d6df8066f011e0c0ca4a3beeedf7fecbfb9bf5d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/adc@sha256:d289bfafef82cc7e38be0a83ef6198fc5cbd74c12877ff59142d4818a03f26e0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/adc@sha256:de794bbbd898cbfb049c53e0af47398b36bfa624d0e1639d7dfc6070cb6d67f0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/adc@sha256:869f9aa73fee42293052901a79dce2da82072d61129c80da9bc69e569b142afb