Sign inSign up
Cass Config Builder

dhi.io/cass-config-builder

Cass Config Builder 1.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.0-debian-dev, 1.0-debian13-dev, 1.0-dev, 1.0.22-debian-dev, 1.0.22-debian13-dev, 1.0.22-dev

Index digest:

sha256:775f665f923dc3cf6c0c1b381f6362317ba5bb49fef1878f656faf154c2ea611

Manifest digest:

sha256:b4ddebbec41b22010012babd0b68158b7c9514d655c312eecef64f1206352067

Size

151.30 MB

Last pushed

8 hours ago

Vulnerabilities

0
3
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cass-config-builder:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cass-config-builder:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cass-config-builder@sha256:118f9e98cd32cb3bf325254772c4cf726ca4d08bf769700d7edc2024f7550d40
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cass-config-builder@sha256:b9e2874b08c9ad2fc626dde5a89762a9e7c3c6691080f2232308a1fc1d402834
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cass-config-builder@sha256:e2e3f171b11e414935c2bab37d120cbe4b397cb971cad60289eccb619ad719f6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cass-config-builder@sha256:cb248b9ecd93c02e436c5bd43e67c3c5204ca69c0afcd0784c118a6b4b25e922
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cass-config-builder@sha256:da42c40d0fc51d33fb72a9cfdfee52bed02b6be585ca3addd8fc86fd427d73ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cass-config-builder@sha256:b5ea82bb5c015622fc2903dfc0be1a2c9a45f1183f0840d158f0accde555238b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cass-config-builder@sha256:56c174d10a6ca60da5f87b0bc0a1cae5e488ceed3474bcb61f887f5cdba10711
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cass-config-builder@sha256:5407e1d150ebc32f24db31478e91c37a1dd417ee79ddcd93949d1fefec7754bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cass-config-builder@sha256:4c4ff55166ff55cbf7451af5b01cded8f147fdc8b44468b1f1589ce2d5c243ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cass-config-builder@sha256:ec59a9909054c3b0616c467705b4e4430ff5582969009f5864deb64b2fa33839
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cass-config-builder@sha256:bc8d9c066495c4b122f2a20b3d8ba348f43b9c6ef2d1ab3d3094f872cb99f535
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cass-config-builder@sha256:e2eb41f9afe7e03122dbfda2717ddae51a72daa66d544e64d8b5d23237992b85
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cass-config-builder@sha256:0828ec5696c515793efcbf64210c5445625c22cfb6e150df847b59578a5aa0ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cass-config-builder@sha256:60144bbe0bd89ee7270c0d93b3f5310ffdb90f0df34151e60dc46126f08d69a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cass-config-builder@sha256:ea7173e2f7b881c4a8a2996fc65738cabf8b80a9683a1937d70b0ea8fe6e19d2