Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.3.x

CIS
linux/amd64
debian 13
Tags:

3.3, 3.3-debian, 3.3-debian13, 3.3.15, 3.3.15-debian, 3.3.15-debian13

Index digest:

sha256:2184f14458d4789e6c61594523a590aec9ae296edcba70a66d24b13c5aabe12e

Manifest digest:

sha256:e379bc599226ed418eac4436a4275d3d6906a2a98852e70bf73eb8347f80ab44

Size

113.96 MB

Last pushed

10 hours ago

Vulnerabilities

3
15
3
14
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:270078b21c715161040e33a0355bdf486080b0dfad1f469236b36e3473a805f5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:022c363fc68c9b05beccac6df880d05ffe7db44aac380c1f736e6cbe2b4fd383
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:99c3d8d6271f8882ec8672e17ca6b79f69428c7bf442fe7910018869b6ee1702
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:829c25ba3f2b0930070e27e2bc328c69d5c36e9d2b428fb002e010d96bcabf2e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:7cc0da4572a6063f74ebf749333183a30217ca579b0834223e53c488f5d1f0c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:3445662e81e1bb338ee364185b3f14f04cfc4d32ef6f6e994565d33729b5bdec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:3a21b5016f08ca4ac16bee873363c0c80097f19fa132cdc07a1aff9530c07d56
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:6d1a8703597a676a9b8f5c5b50fa6aa0d3ad2f57945991e73632fc946169140f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:f90836f806ec1910f30a98d2b0cd9f81f965c7eab5e5cd23dc4f174ec20aeadb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:adf1e7e8e6f5d13f41c230a2177e952fd02e502d704ae7a0cf3d5fbdbed6474a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:74ebd5b6561e3edf1192d480699491bd92d5637eb46e21cc1e3d60a8e6f78cd4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:bf2bc281b63b8ca605b337b79d68af94cfc2f422e50dbf3464032c927a6890ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:3a26fdb9714d3f8dfee6c5d86d88df30c116d21e1608409912def10b35b715ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:19a1c80cc3b93ede8e63ec8120c04d6fc5c3e57891345783daa0c3756b70bfb1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:3c4cd1ab83bb02b89051f37820a31622cc07c6dd50c7e10d7a124e289532b26a