Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 3.7.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.7-debian-dev, 3.7-debian13-dev, 3.7-dev, 3.7.18-debian-dev, 3.7.18-debian13-dev, 3.7.18-dev

Index digest:

sha256:e66d5720b5a65719e4fa00da33b01a114acc7b949b8553bc97aa3517a37a4161

Manifest digest:

sha256:451a044fb91b3d01d8687ee78a15e0970561d71bebeb2ef7406a9f46424895bd

Size

87.20 MB

Last pushed

23 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:b5092c2dc0e4d5acc9927348f3ad5f354294f33fdca284378229c5e66a86164e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:509276cc2d2cba84721890f7678a9dce9361dba77540636f358c14f5cd11c5f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:df31c287fa005918a43a1e55693b9862e025a07f96f59bf58275e036ab69e4d9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:12a163701276e8cf29c469f746b93c756a96ebe6b72067c9e5e4ccdce8a44b01
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:b5db0899673bbcc43251f288116e59d06da60d2bf6871f344137bbbee4b3b8e5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:537c55e70562d37a81e724d3404409dd6c05a0b71cdb7b85d2ba122f53dca66f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:0edbbe254b4bef821451265101de0e40a02988ad4a43092240f6b5c984cee290
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:8e2f7d9623a8a55571b116a27e89b001a26dcc03bb27784506ca6baae590dc6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:5c634ad6fdeddda7f25912bc590ba8e8cec54e9c0c15d6e6a8bf5ce97cfd3da1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:61bd55d158c64fe3e278f5833f301b945cc89fce1f85513202a670297661cce6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:425af2af889158286452e9d0e2236d546d001354e75770414054d1a83de93bb9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:664d11e088b6c6711093c282609d4cbd85c2fabb78c401c6e5439b48e40646ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:c5bf73a41952744d1ab67fe4cd76accace53bcd10d22440a32be62698d72dcce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:d011ba0bee65305f97a195972cbcd4e05627149f884f9e6f895a255bb3ec7784
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:179412e6c46fe0018a7ee7c65e2dee25ad4a30b7316dabfe37df0c2fd73b9a9d