Sign inSign up
Certbot

dhi.io/certbot

Certbot 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.0-debian-fips-dev, 5.8.0-debian13-fips-dev, 5.8.0-fips-dev

Index digest:

sha256:106b8d826b6719789efc9a5bfd330e229e60f3b90d9ecb499f5b6e3d17554508

Manifest digest:

sha256:7c39f5175957a55f3fadb4129c9b36e9ca6ff9b1d5af044537770cef8d9df1e0

Size

37.80 MB

Last pushed

2 hours ago

Vulnerabilities

0
3
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/certbot:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/certbot:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/certbot@sha256:dee64e852bbd436ec0526c754f9a13cdc27ca62f7269d93e5c5cc35b89024573
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/certbot@sha256:bac3cd40c6515ecb094b155f39a32f4ad4f83be233321897c171771f25825b30
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/certbot@sha256:dad67d15961ec4e0fd9107b091a7f5ff3b3881c4ca52a8dbed478049fd7436cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/certbot@sha256:3fc7b9ba97acbec504993045a4ae42e0c77675220e0b1cf2d8c6b8318b67f83c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/certbot@sha256:974459621f3ce64dc3553f018677b3051fc8a2a732f2d20b375ec075c89b72fb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/certbot@sha256:49fa82ce58fbc5bd0e6d31d79a242b6746141a0bb3c86df6b9df8dea8f818003
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/certbot@sha256:dfffb7b23f2ea6e00181cbaebd201e43887f4b37cdd9a5ee992cf37d7bee9cc1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/certbot@sha256:2251151e7c2695e7f6dc79013e09110cf9f27609c33fca36a9c721b58fcf50f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/certbot@sha256:7bf1c42cbfe692f417ef54c271eb1ee6afeea6b254d8ce5655817d85a650796b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/certbot@sha256:ad85ab1fea4ff0ba4092bd37bf23d7db7bdaea77cbd45647ea6da0b5ee699fb3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/certbot@sha256:bd326685cdfdf4f78215d40faf7a6ea579c0261aca6a69d6967428a513f2c000
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/certbot@sha256:c1c7dd7c7420983ee48ecfe3c3f37e28c0574f3d9f3243acce09668109eaa376
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/certbot@sha256:16afc771395784f506780efd0614e3d860aef7524fbcfbff08113406f05c2842
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/certbot@sha256:f45118325b8fc9610fc0a9cc1e5f402226978ff2fe4d4c7670654bf05eac969b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/certbot@sha256:1808b25f3f753027ac990714d181525c1bb5d2db5049d5a5360f7d9f34694e06
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/certbot@sha256:1e8347857a654c44c465634ba2ac26484282019546727d3bd5fd6528f7e77dcb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/certbot@sha256:d0c3c805b87f848109c0bc299a7489df1ab3c2e9f2b04e6f6fc81afba6755438