Sign inSign up
Argo CD Image Updater

dhi.io/argocd-image-updater

Argo CD Image Updater 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.1-debian-dev, 1.3.1-debian13-dev, 1.3.1-dev

Index digest:

sha256:48de8d50e22425fa9916ad40210df263992bbf06c8b1c96445049508bea7e4c9

Manifest digest:

sha256:bac683ca4a34efe36b59b1e5f06b38ce2a12d9feede137dc8bc46bfdcaf7590f

Size

131.17 MB

Last pushed

8 hours ago

Vulnerabilities

3
13
1
12
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd-image-updater:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd-image-updater:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd-image-updater@sha256:0409757a375ec7f13a12096f6fac85e152bc2fade7542b74277f0d12df540ea6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd-image-updater@sha256:d590404e64c54e2801f75fef48d3213d805a4c27ff5faaee914e46bfa9e7710d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd-image-updater@sha256:9126c42030ac5ff89b3a65a7c4b3702a1498fcda475f4ce869d11fc00965a112
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd-image-updater@sha256:592dd89996907bc414436d40f2bcaca18c7c2f9329702aebd0f1141f16588c95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd-image-updater@sha256:b49c561c21535016eb2a4bb85e4ed84f2043ccb35d242767792b1e61082f64c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd-image-updater@sha256:2c250f5c43363dc8af99fa7d8f6e55a0564c492bb67b1b5cbec3eaf9eb7fbcc0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd-image-updater@sha256:33cbc857f1bf69d41010e65d8205b324a29890aa10f33345d2759b97d5c0b8c8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd-image-updater@sha256:d19239b382166558964841f15f3bee2829f1cd91d263fcf393d86e2b2ee37d71
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd-image-updater@sha256:af85274447586e193c908e71b30ec64f7da9fe94bbe7171ef18d7b6a18574ad8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd-image-updater@sha256:7f02d3f94e0c660b69fc8825b3459a8a0148b3dcebf3e64db7a020c79a7767ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd-image-updater@sha256:d7bc568b79ab466687ac45c1f028c9ac7fac1c358527e36176c824b80e1a14ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd-image-updater@sha256:58891dafd92743b40bb48752959c75642e502d91741a70e74d8549eb231f5e25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd-image-updater@sha256:d283fc0e0277c082bd03154cf63a58306c8b74ecc569e4a09f1d075d3329b718
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd-image-updater@sha256:26c7d50e72a69b6050ab0a7bc260150ec05df00e04d65a6aba4202ae4c461c29
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd-image-updater@sha256:5ea76567b83b6aeaaafa34ac7af47303c840be94ee426053a8fc3ee0e673dd20