Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3-python3.13-debian-dev, 3-python3.13-debian13-dev, 3-python3.13-dev, 3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3-python3.13-debian-dev, 3.3-python3.13-debian13-dev, 3.3-python3.13-dev, 3.3.2-debian-dev, 3.3.2-debian13-dev, 3.3.2-dev, 3.3.2-python3.13-debian-dev, 3.3.2-python3.13-debian13-dev, 3.3.2-python3.13-dev

Index digest:

sha256:9b954a13b3e289bdf54db30de07d38b4d3dba6072c19866c5eb6745ba5c6afa1

Manifest digest:

sha256:489fa9a06a51767b71a115fd573f2b2c3672ce9551da744c085ed9c525d76e10

Size

78.25 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:6c8c3a6a997d96409cf623da6ec2a39aaab7f5319fa228aa24fc23a3d97ae029
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:7de5fde52ddc861a4b8ac5d60f5b58723a599f4b7b2d733a9d13cf952cf0d059
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:654423c1c1f8ed6be38405f6553e175887e01c0322e0fab4deeb9d7a3fade893
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:ba1ca8a22fdf5cdb56efb93a484823db7b5fbc40d50b95cf20ab753ee9026afc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:5180d67b0846be64d353d78f2293eb923dd0125a6e0d75551d235c2692f04c21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:26587323f8b58f6cc8a250fdd25137d2cb6349e88bcc6e5d5da3c2ae8a295654
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:836682ceb42e446d437f04cde401ee4be1f69bfb74f863a37dd2847b88d418aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:465e2fda16d8490cdaefd6ad52959f05d3930298621aa2b53ab57475bbc6bbf0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:4a7e01a3356e4bec9373487377d926c890e81324652d7e0947c8998150c0916f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:5fc955e87bd73896a8f6d451d7e7fd4ecee048101ef080205e7d0527767cd514
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:e778e084bb526c462a546b5e4cd18d8bf959f67deca4f2f28c8c859685655514
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:7da2f4745e5659fd1442c76f7e4e8536b7b120e79d0c9dbba332bf9b1a1cf455
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:177e40c360a7a0d9356593e7de313f9e481fb7a825efa5c3acaa0cc26e149826
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:0a51814adf4e27f62b24411e4d41e4363cc0b3a801bc35d615b2163d5ceb0d35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:b9412704ca74e8435bf12fd3d48c900c4c2882b6b2c7fa4916be54f6f891950a