dhi.io/argocli
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.7-debian-fips-dev, 3.7-debian13-fips-dev, 3.7-fips-dev, 3.7.18-debian-fips-dev, 3.7.18-debian13-fips-dev, 3.7.18-fips-dev
sha256:69f07352ab3af6b8a26735eb8a045fc631b04b9e437fadf983eceac099954f45
Manifest digest:sha256:252e085cc2e4ae91258930efab36195637c352ca12151f8dee2fe812e004d38c
Size
88.07 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:08fecd3d04033c28721678e80a315ade5aa2ac3c21e48b0ee2cb28b2b7056b67 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:aeb56df33b5c44734d34df1eebaba146851468b9333e3b2f4ecb7c6028e6b909 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocli@sha256:7e401232c4be5f97d339f82f4584e78e4b155b3f8547a4fbc8dc600213ec0d8b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:db492a85e8c2b1ee573cc7adfbae905efc8685bdbf1864b22837e85b060ce1bd |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocli@sha256:e6d2d7a5796fba29b7dfdeed17a8b48d683341f74f631527f0797fb07d520686 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:7910cb0905f3064171f51db6b1b700621465341c9d61407157ca984a8704bbb2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:aa7602fc906ec38c5474a4c5b5fb13eac3be40a2b643870acaf2f49e43ea2463 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:4526fee15339ad5c94271f4505c1d90374ca26c177e237c0ef55639852780cdf |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:6a39409d2f277190e404efc1661dfef31cb0dbeb1dd6edeb6723b2c8446f7eb8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:157270b6f5cc39f08170f301b8fc90d8e871f6cbdb38bdf76247b0d498af465f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:891ea268c8a761251f8ba2c829ca75570aed7de43b2925c6a2286d02f4c2395a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:7077ab5e102b51703b06c05af1219d1402915977970daa9e5145fc3fa1ece720 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:e8e20a1446256e6bfcc217183333e61f4bdab8d57f62bbce4811a75f3d37effa |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:0af2c612712025c67c3b9a0713212869fe4bd715f8b028f7abafe0e9158d1833 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:55d0c1097ab180112df743e3bb8372ae0fef74c1613b5363cda17bae99c243f0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:f98d9b0e104f12ceeb0ed786655748fa7c8a6336d37f2e01bd5b0dfcd6dbd555 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:aeb7b5ce4e3c338ed25fac9e2369983c0255c549c49fcb6e3e9dc088ddd37b2f |