Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.3.x

CIS
linux/amd64
debian 13
Tags:

3.3, 3.3-debian, 3.3-debian13, 3.3.14, 3.3.14-debian, 3.3.14-debian13

Index digest:

sha256:7ec8d0ae6b921a9cd0031f0891a85512bd94c713e3f77928d5697a9d0bf2107a

Manifest digest:

sha256:7d0bbc4fd52d0ff2b1d9cf7a8157794fb0fba03c3e9c63589b430d2f115d23c0

Size

113.95 MB

Last pushed

1 day ago

Vulnerabilities

0
4
2
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:5343b89455c0d571a90afa44bca8a7ec7ee1b5083829b9549b09f6bbfae90c29
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:d1ad816b1b3ef2c3a054062391ffa82dc6d70c107b11fef7013a8915b796e25d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:d0a52370a90bbfb868257ec205548be89d012bca123568ec5647056456dc40d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:0e4e391ce8381fbdab5bd9f0f9bd5c8875bab2ede1541117aa498a8b9044f244
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:c624e9f653ee52c2238f014a42bb437beb0afb695ce427dd33e625e5d541bd5f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:e31b2f0145e02a92f2fc11f72bb6b78294c48acacda36483eaf597fa0b423afa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:fa3c694907a54cf2d216fe33c66902f0ef2b2ea5650bce97f07af0e846f8381f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:ea05b8accec7461e2df0f851aca17f5fd5add0c236e1fe9c943212d141f787e5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:e7d754aab3bd0372bd98606c90f7d579f4fb24f4fbe6428cfb8abe931a7ad50d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:690bf53dbb8787e9d3f93665654d73e8a2d5ee64756dfd5d03957593099702c8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:46868a8f4c6ea47b1c2ce969fd02301f54af862e14815f51aad35b973128657a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:ec10a4a8a4c3ade71d8149190806cfc1bac7f012d67a058fab3befa2952ecfad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:60a21f7e465b16f6dabe308a0383a09ae0eb6255926b8acfa4cc4a3feec51a2d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:79928733f9160c9f580487aed7136b6f7ceca17191db27ad6b3ff19e9d857837
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:95309c549e1383e2ed4dec8743e74b1c33bc1390db7a61d6784dcb6c0a85d5b8