Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 3.7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.7-debian-fips-dev, 3.7-debian13-fips-dev, 3.7-fips-dev, 3.7.18-debian-fips-dev, 3.7.18-debian13-fips-dev, 3.7.18-fips-dev

Index digest:

sha256:9c010c2f822a7ed5638f92c1c19baf6f4da63f064f4bf2258c7d96e00f501e08

Manifest digest:

sha256:e39953d02ecc6a3fb8d044461bd8b603c94abe05d06332daa2e9aec77b66ca24

Size

88.03 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:e69b394afcd216fe3bbee2bde30235226d9ed15b54c773a5cf4a8ddc4639ee96
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:222d69920f5d247c5d0167cdfc1f5be6c35bf6c21e5696e9cbe0c470231c1c20
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocli@sha256:e55a3535a7c18788bc81f6c682d9d63529be311c1f60c51d3d13a9532833b709
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:d0855bff9e66b1b8b52297ceeeac1aeaaa81893a2b767db879e5bd6f04373255
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocli@sha256:763ee5eb334d9339ec20540fdc0cb8a94a2d476680186dd9367944eb782db749
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:0a60f60715a4ecc7cf91a61406a86b8439c41d679f131f9334e43cfb4aead4dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:968c479db694854531f8b6a33c006f539ff3f351f99295785c4cea8b26bd8d99
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:45cf97036a403a74f56d1dcdf44893726a9df06cf55c6a709a1617ef74f8a98e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:f15397d188daa16bad279b6fb3b5fdd60a162ac9d7653f967fb15fa18060f348
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:477444e5b7e0a6c48d2e0d8e2ecc2dc109d8cc3aae3bb4d942111e72b26aec66
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:3f459579525651904b01a82a8c0d317e1a819643f930c6e44b7fc7c063d1e829
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:f921f37723cdaa6a0d5b62f682525e728e62cd613e47c999d893e8bb2bdb7f5b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:aa6940d369fb9c0b2d7b4d5fa9e0a59049980da95e4c4dec1d6df5ef8c9f960d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:bdef62c11bc8945f1c9da3787200ba6aa22c8348c8424a61b6a8affb8fbc73b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:ede4369f9ff64a2763fc820f1cf59c1fa0c5ebf930f47a83ce17ae5540add9c1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:a6a854f652e03188196d61f97f9a0fa443bdfcc9bf1429478a55740d8a8b7c3e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:eea8d7e276b3c7cd967f6e62a65098401305b318eb408c0f7ebac6709f2f7952