Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.5.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.5, 3.5-debian, 3.5-debian13, 3.5.4, 3.5.4-debian, 3.5.4-debian13

Index digest:

sha256:d3132a362b4521c15420541a2d6738826eba6c103e506e414a6d8096b2e17efa

Manifest digest:

sha256:33abd3c063114f8783ded1b7ef94a6a06f22c8bf33ad6094655e93c4dae71c60

Size

114.01 MB

Last pushed

21 hours ago

Vulnerabilities

0
3
2
14
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:2d7fa22016c809c9e7c7ed2d36c164e74995bc1673eada1f6cd48943dd6ec090
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:a364be221e3106b7ea0e527e6ddef9b2fa38b225c20882f2c0db0c746c3ebb96
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:158f3ff3ab957acd76354c8da2a9fdae23621ed2bf4366a5201cca48461107af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:a82a497dc6a7f7e41cd419a74d47e45f17b4207aecf71b0c7a17ba4e9b8d480b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:9b7e4cae85ead3ebfc7a9b155de0ccbe0f9ef87e5927db6dec2bc35c714d28fd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:abbcef73bca04f6e5969169e99c40d29415496fe5b1e4595bc33ca1edc783309
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:6c0f1b8d440f6c5705bed3aa5abb9a3bf23e8201e8d28d476de0a54911e64ad5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:cbeef8b00d7d1f107f682ac8adebeebe5768a1436f0b41ea53d78f4405c98842
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:46a900a9004454976f610d79c15f411f9c64fd9c2ca9e912ec889cd194b05372
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:97008b4736507579ee04357cd7c66e58139bc59bb844599f027f6795cf10c5f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:a098e6e701a5186486c3de7815fdd991539639881a1ca76cf0b2df7fe99a70da
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:345acda551d7960d2162a1ec231f89a51f4714158795a27797633a5fee9e7ce0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:b5a20b67517bd1cf139dc1528fc2f70d34198834dfbd766431a034178b3a6e31
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:25483b2f07bf9eb3f2ada4f1961c6fe92d53df890a25fced4787541d80f2d362
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:3cfa45caae8b0ece4abb66619fbb9a90a2d22ec7dc5a5b0bed4292cac18ca4dd