Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.19-alpine-fips-dev, 2.19-alpine3.24-fips-dev, 2.19.0-alpine-fips-dev, 2.19.0-alpine3.24-fips-dev

Index digest:

sha256:2f2d1e91329cf455a419911e261207c52300a255866766e8b3b1f3bad15397ea

Manifest digest:

sha256:ea098edaac5574adc091224805b2ef6d4c0b2f8587f61a725e8848dca9bb373f

Size

27.42 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:755ed1fff56489899e8dc677c2f16ccf5aba91f0727bcbcdf749eacb59b00e38
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:3b85e74fced67b4333412c235fee067c16fdaf1eb0c322e1171a8df5cd5bc737
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cert-exporter@sha256:621ec98e0ee10a200d55979aa2179f5868584e46327a405d4b2cea80363aeb08
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:48f70578eafaa429425a8b90d265ecf62eacbb2fb976e3223636a2b78987ec8e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cert-exporter@sha256:228f7200a08199f65878efb93e1fc9e841c8c98e73b42fcf07f47b0c68e4150c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:0bf6cebf1d92885dc74fb022294504a2d017bdc917bd36533ce3d8763ae900b0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:2fd3a872dbdbb4abd3779bf1f4f3b542fff72b0e4995ff365311e6f5aad0b0c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:6bd4ffe389aa873f08b7bc131a8c2924859b90fe25ed584148d9e79ffdd6afcd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:d4b3eee95b873266d960100252f66feddb5df232d26a01f823f8424e56ee66d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:bab8da22cc9e0acee1140ce58323eafe65fcad93ddca0acaac4e44ea5514b80e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:5a8d2228e3206577e9bbd0b6658ba60ce85e05773550c6eaa1560f561ee2f53c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:dadf5a2374519246476b72b57a9bca47fc260e55e6dc2ea33875ea513b726a8a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:b51d4dfcdbe12c192069adf652d1c66539abb1e6ddd040738422e3ce7eccb0a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:f15e29b78e82e7ca10f2c8f5773fb8d4a23f38971cfd911fe2e9e1e265a12686
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:9c2e6cb476bc3334a938903d8768737692531a4853ca4ead8e3ef64de3436665
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:457094c9bf2d2eca2e95f86706c3a45743b74880cde06052ab59da867f6560d1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:93f7f80ce5e966659ae50a9fa735ba4401f37788ec93a544bb14352652fc2c2c