Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:4eacf25469f4e5074080d4627dda58cf31faec2d23f1d39fdad19fd660923810

Manifest digest:

sha256:05eb251b57b19c7e6ecb39d6cf7f4c68d092d799638b0139a119d7f071a5ddc3

Size

116.68 MB

Last pushed

16 hours ago

Vulnerabilities

3
15
3
14
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:4b68df4deae4368559349e5913fc9f0ed781038283d36424fda06569ee186e79
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:cef3e6edfef9e56ffca08265a6aa072d0b8833337b95421e2ee47f54574f4b7e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocd@sha256:f0d7c6ba39aa4ec6c57a79254bd5bfe6e7fe12204f0daf0a1cbd1fc5c9ffc622
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:f599001fe0a0f08305ba00673eceffd7142f9fe5603b6c93326f3dcd7f56222c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocd@sha256:b961ae814b8e50d42f61cf40754e4f26fe815b1c618437b557aef1a8967d4a2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:e9c0568e335a2a3b1c5b95237e9d3ec20b968d5802427c3af280569784c9537a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:2d14ef9361c2ccb6d5d6f3e8122f98db926da766a12e6d48de3fe08be36fd20d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:b222210655856dae684ac15fdfb601dff8c9ebe1281c81ab391336ab971be679
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:a0d7396b421aadb4768ab97309b22c66a0e5436cc63378f53bb476993a2a9f1e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:6c5b363ce0d13e5422663a85e5763ad25862d9bf507b246f6f519e0f922ecc96
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:f486d5ec3be043c36c959e9a3448d747537a64bc77752d84f6c2ef5e1830c381
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:8980aa167f9e3d6d53609fbc129acb604cc35e2e7b8f86ebbf739badea155066
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:ceed19689cc1c167738e18fd1812c4df6766f0a3cc71191727f3b6aabc5e3646
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:8eba13f2706ff6a5e3a99849cc3e3811452e228e3d1fee1558d576f8777608cd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:35eafed80261c56d8f805c40b070a188621fa2cb26e9e90fc8070f99629313a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:4af5b6f898f5fb889d5aaa61bfcd908c2e2dc119fd50d008e8b880897e443556
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:c8e1b3c7aa656a017fbd4d0e0dd5e76ee572313201c222378aab84a0e54b7f0a