dhi.io/apisix
3, 3-debian, 3-debian13, 3.19, 3.19-debian, 3.19-debian13, 3.19.0, 3.19.0-debian, 3.19.0-debian13
sha256:cdbc06f6ac5a580c331a8884b93e9c1e52fcb232b174e27e1e2e4325ee3d5b39
Manifest digest:sha256:114403002c0e79dac65f9a208b9058eca83aecfcee532da99ee9dd57cb0aec8b
Size
69.09 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/apisix:32. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/apisix:3 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/apisix@sha256:52c1ec0fecd4546d74ed4495db060beed41ddd669b93856c86ce5419cb883847 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/apisix@sha256:49fbd17963f84394c7d2512fd0751f9a2bd553abe1c4828fa4528490f25b5d41 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/apisix@sha256:d3f8ed7ad13d343642e93d68d8b60c6a9fb659c971e5f90dcb7120260a11dd0d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/apisix@sha256:267dfcb63fa14b3d336d470a28fcd96a0f3528f0319ec0bd32d02ea5ef7c107f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/apisix@sha256:704efa606b4f1aaf4c2e5fbfca8a79517b3d0f45470152841e6841d5771422fd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/apisix@sha256:06511628014b71ac523d4e5594acb70ce2f74f64548a87c4dd3df8fd7d807d07 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/apisix@sha256:2a8e15cc8daa2eaf6a6dc1290e372a35504ad2935f45f7858a13238e2308e23e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/apisix@sha256:ed20c75f2c491e67bbc42513aa2a16e5b0c1fc63adf61041c2e0830412a2c0ea |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/apisix@sha256:34ccd4fb2f2c79d7781ff51aebc35e4289655479bfed3285065eeee839994b30 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/apisix@sha256:c51514e859c1385a977c3cdb9094e1f50862d46f28f930c34a460a08f6878d63 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/apisix@sha256:d34bd7a5b117dba13036a716f83027649a39b6328f4464603a917006ae7628e9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/apisix@sha256:164fd772c5958133f77164a40a03b274b2b6e2fc9926b19515ff0d8143422b04 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/apisix@sha256:8a5639ec8d776504c5a3d6b9106b5b6d73bbcf05d398fe50cbbdb630a5f1f93b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/apisix@sha256:c36e81cc994576c9c4aaeb31998415d1447d9741e1abe68c38578fda1dabcd49 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/apisix@sha256:b4c76288c0ca1ed39dd88cebb38c6eeed7a9e9e79b9e7a14acb2567e3e345a07 |