Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 3.7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.7-debian-fips-dev, 3.7-debian13-fips-dev, 3.7-fips-dev, 3.7.18-debian-fips-dev, 3.7.18-debian13-fips-dev, 3.7.18-fips-dev

Index digest:

sha256:69f07352ab3af6b8a26735eb8a045fc631b04b9e437fadf983eceac099954f45

Manifest digest:

sha256:252e085cc2e4ae91258930efab36195637c352ca12151f8dee2fe812e004d38c

Size

88.07 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:08fecd3d04033c28721678e80a315ade5aa2ac3c21e48b0ee2cb28b2b7056b67
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:aeb56df33b5c44734d34df1eebaba146851468b9333e3b2f4ecb7c6028e6b909
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocli@sha256:7e401232c4be5f97d339f82f4584e78e4b155b3f8547a4fbc8dc600213ec0d8b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:db492a85e8c2b1ee573cc7adfbae905efc8685bdbf1864b22837e85b060ce1bd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocli@sha256:e6d2d7a5796fba29b7dfdeed17a8b48d683341f74f631527f0797fb07d520686
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:7910cb0905f3064171f51db6b1b700621465341c9d61407157ca984a8704bbb2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:aa7602fc906ec38c5474a4c5b5fb13eac3be40a2b643870acaf2f49e43ea2463
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:4526fee15339ad5c94271f4505c1d90374ca26c177e237c0ef55639852780cdf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:6a39409d2f277190e404efc1661dfef31cb0dbeb1dd6edeb6723b2c8446f7eb8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:157270b6f5cc39f08170f301b8fc90d8e871f6cbdb38bdf76247b0d498af465f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:891ea268c8a761251f8ba2c829ca75570aed7de43b2925c6a2286d02f4c2395a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:7077ab5e102b51703b06c05af1219d1402915977970daa9e5145fc3fa1ece720
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:e8e20a1446256e6bfcc217183333e61f4bdab8d57f62bbce4811a75f3d37effa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:0af2c612712025c67c3b9a0713212869fe4bd715f8b028f7abafe0e9158d1833
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:55d0c1097ab180112df743e3bb8372ae0fef74c1613b5363cda17bae99c243f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:f98d9b0e104f12ceeb0ed786655748fa7c8a6336d37f2e01bd5b0dfcd6dbd555
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:aeb7b5ce4e3c338ed25fac9e2369983c0255c549c49fcb6e3e9dc088ddd37b2f