Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.19-alpine-dev, 2.19-alpine3.24-dev, 2.19.0-alpine-dev, 2.19.0-alpine3.24-dev

Index digest:

sha256:3d08c44fa213eee677c78946c76aafad9cd2af4e80491350a4f0203d4b517c43

Manifest digest:

sha256:6bb8eb986a6fa0480b95a9227d902f4f4f96fb98fe627069035db78c8145701e

Size

26.60 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:c15b7ff2b70e4c391deabc2cf5cbf65c6413d9ae1a216a729fcba76947bc2ffb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:cd6150f887452ef569df78df182bc553d47c41bc17d986b5755ab8a6fd5818ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:4b45d84d7e9c93c9db1b3c58c1c9d13b9f9f3a3d2aa182f1b5b6dd545163c568
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:4215c91b0d8e7e536944220949c1704835ff1bae1344fb4e597c6ed0dfceaed0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:e6f70fc3719d72c2016ad110b7e49222ea831660bdb6c2fcd51a8f8c0ebaff85
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:1b11ec47075a32f53c01c6b94e6737d49d58b4032d9cd697706890f53e431d83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:972db727085fe5231d69af441671c75d28851877459dea46443321e033a15c80
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:ee308ec519a79219fc1ef9b6ca44a7ddcef6bcfa678f12d19f0f2a2547c4cc88
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:fb8a54b01527bfcd4eb01a9ec8d001888e2574fa2190ff5788c2a5aff8933d3d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:544df522a99c7bc2a91a0dafd36335c6ae079117af1607ec1ade0b113a13ecbe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:05a5aee4a5af78967ff61b7ce613d15f548fe95f6436c60cefb475b8d9338a2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:ae4fa90716efae6568b26a295a4c3050114beb6bd9ef4441e54f910a925e3163
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:f71bb69842e20ea509996e64ce14a7b1ddecb3622ec114aba7e6db69e5eb7dfa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:6148aec8a53f94f1921e98c6bd25d0fc9ed0c0f71924d513625937e1e86a6023
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:e077ef83c7907302c3b5bea15a42bf0da60a464a9134c0cc74b271b19e5c9528