dhi.io/argocli
4-debian-dev, 4-debian13-dev, 4-dev, 4.1-debian-dev, 4.1-debian13-dev, 4.1-dev, 4.1.4-debian-dev, 4.1.4-debian13-dev, 4.1.4-dev
sha256:ece07aa5408d5c4ec23814c7b213342e03cf1e417d2220325847a4e3a4032a56
Manifest digest:sha256:7e527532a02f2948c14da8ca7f0f17437f603ebcb5aa3e9590ca3b1310ce8bb6
Size
89.31 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:4-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:07810f225faeec1ee8736d04546d3a33a3134acda7eabffb2175346451c7d95d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:12a3862c396d831c610209a27b22e067f1fceedfd4ff1be09e932722b231b93e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:f2f870e633e39fe575ae8c76cac1d64a55e50c5a3dcd216ac90202e99747e217 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:95a0c84dd0c4d736723684693fab507f2027890b9e21db0d6ac9b56efb8706d2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:32392be2cc406c0dc3111ed383b9e1a291c6b5b6bb5c82f1367904fe99f5e1fd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:9b18fcc63b3ddee4a58a1d2603a4d80e78c78eb172bd6060047de6a18736b624 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:0ca1d6d55bb7663a758b9116a454fc6ce17e64d688962b1085a19033b4700b1c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:680e4ba79e119aadfd489a8aac797f476b2295001623010c26723cef8d9a9f9b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:b9e128d58227db6aeaf90321e1f9b8328a2b8f8f9bf54a5e99754864ab56c547 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:cf51af99a4b9018d4dcebfa97744598905c26c8bca98c30ac0b7ac2f92b07189 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:2fa1afaec0588e24a0942143c1ff6d609c6200c167381194d723cc409d3d44f0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:6a704f01aef2cc3bea9e886ae26a1efdd779de7835b71621cfaf2f9378910665 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:12b643fc5c43a6d16b813573c75871e6eca6e7c7766b63cd63edffdf55faf346 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:e21a25e560b5285f29191ada1cc7f1f93dbb11b4d9314e2c190696c206214838 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:51843def6cead402d4874481805e9d275185412b2b1442739fd4d067db795faa |