Sign inSign up
APISIX

dhi.io/apisix

APISIX 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.19, 3.19-debian, 3.19-debian13, 3.19.0, 3.19.0-debian, 3.19.0-debian13

Index digest:

sha256:cdbc06f6ac5a580c331a8884b93e9c1e52fcb232b174e27e1e2e4325ee3d5b39

Manifest digest:

sha256:114403002c0e79dac65f9a208b9058eca83aecfcee532da99ee9dd57cb0aec8b

Size

69.09 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/apisix:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/apisix:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/apisix@sha256:52c1ec0fecd4546d74ed4495db060beed41ddd669b93856c86ce5419cb883847
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/apisix@sha256:49fbd17963f84394c7d2512fd0751f9a2bd553abe1c4828fa4528490f25b5d41
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/apisix@sha256:d3f8ed7ad13d343642e93d68d8b60c6a9fb659c971e5f90dcb7120260a11dd0d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/apisix@sha256:267dfcb63fa14b3d336d470a28fcd96a0f3528f0319ec0bd32d02ea5ef7c107f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/apisix@sha256:704efa606b4f1aaf4c2e5fbfca8a79517b3d0f45470152841e6841d5771422fd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/apisix@sha256:06511628014b71ac523d4e5594acb70ce2f74f64548a87c4dd3df8fd7d807d07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/apisix@sha256:2a8e15cc8daa2eaf6a6dc1290e372a35504ad2935f45f7858a13238e2308e23e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/apisix@sha256:ed20c75f2c491e67bbc42513aa2a16e5b0c1fc63adf61041c2e0830412a2c0ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/apisix@sha256:34ccd4fb2f2c79d7781ff51aebc35e4289655479bfed3285065eeee839994b30
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/apisix@sha256:c51514e859c1385a977c3cdb9094e1f50862d46f28f930c34a460a08f6878d63
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/apisix@sha256:d34bd7a5b117dba13036a716f83027649a39b6328f4464603a917006ae7628e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/apisix@sha256:164fd772c5958133f77164a40a03b274b2b6e2fc9926b19515ff0d8143422b04
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/apisix@sha256:8a5639ec8d776504c5a3d6b9106b5b6d73bbcf05d398fe50cbbdb630a5f1f93b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/apisix@sha256:c36e81cc994576c9c4aaeb31998415d1447d9741e1abe68c38578fda1dabcd49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/apisix@sha256:b4c76288c0ca1ed39dd88cebb38c6eeed7a9e9e79b9e7a14acb2567e3e345a07