Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.19-debian-fips-dev, 2.19-debian13-fips-dev, 2.19-fips-dev, 2.19.0-debian-fips-dev, 2.19.0-debian13-fips-dev, 2.19.0-fips-dev

Index digest:

sha256:01e7aa1dee547da853571f319fa948de58bb58a87f70b4cd2b53e466bc3be341

Manifest digest:

sha256:a0c2016f10a191b16fcb0443eaad2a6aa7352d9b4bb4f99748b46eebd27e45dd

Size

46.72 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:2934ee7cc4d99f3104fd93ec00259719dd68330cd743e411abff71642009eb49
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:3df254f026bb9efb9bb5c1d26b0b581aa37a695ea170912ab67158344505e20b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cert-exporter@sha256:98a7ca841a7bce53a44d47bc00a642f26f39dd8e6570d5c16adb52cf68c27f23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:f9971627a9205f770f3603950e4516cb66f85c8b5bb48e33af23bc4c2c6b4a89
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cert-exporter@sha256:db826e3e33198368f1e0dc89fa82cd82022769dfaf711e4a50d70ce87ba4be45
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:1f81d77146b5a6dea56fc7bee4c87e0ad0f7cf5e2be53daf8cbf94a8e2364857
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:0798c11327b7d7e2e7ea08b047bd001f673fc4aa1cb977cbebfdbed248b037e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:2899585e2a28afecfaf790cb0571d8d6b3628cbf63c70badb4e6ce5c0be2a38f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:5f52ad3527b5831cb40f76631108f2da17665eab36489fde746a59c344789e46
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:e6f574f0fde202cb75c00887aaae72eb1dc1c2fd1cb0e0e78b8ed87023d1ec5e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:e648969fba433db6cf4d10711a9a9fb1e47fba64e3f15dcd452516077009b4dc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:66f89d9d9184dfae2726da93743b16e5d144bbe2dbdee179169b4f5a2d49f989
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:a8f4f5dd44d9c6c3c2a6a62234e2b67dcf8d9337af9e9e355a83d78bf2136d66
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:6826a3e5d7b62237bf369309a2c7b6cedb847376dc75447ee8132027dd713b23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:391eb5f4972c359304c10b751bbb1d0efb59336ff610645a248deaa56552150d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:b50e35f91b5334f48eccec2fefe645aee7273f83238e203b4386df58aeefe9e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:c7a8ef0bc0d87898f78b3771b22c933a7cf0f17dd66b58925f91d903eb2fb93f