dhi.io/certbot
5-debian-fips, 5-debian13-fips, 5-fips, 5.8-debian-fips, 5.8-debian13-fips, 5.8-fips, 5.8.0-debian-fips, 5.8.0-debian13-fips, 5.8.0-fips
sha256:d25e2db08d7c3c4be6c5f91d316bf202edb0b23bfa9d5695bd8052ce4a537a5e
Manifest digest:sha256:ad7cb36c861428cae75d7b5361c5de0a03e37086e22b38f502f2b26b1a32aaec
Size
25.37 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/certbot:5-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/certbot:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/certbot@sha256:82cbeb27fb7a57fc32fdbe4ece9e7569b9be6f6e7ade6d6f57a95f211624db06 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/certbot@sha256:0707aa8c2c6770dc9c4cd41e6e6d946f113755dd4aa2efcfc6872b038220bea8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/certbot@sha256:4a5a0f913ceddfe9e651d565f902ee7fd472133cb7aa78ace9f5b3d44acbacf4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/certbot@sha256:685e8c046f479da3353b2513875b1a41917124ee6ab7ea0adbfba8a74d49784c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/certbot@sha256:296ee28c355d70f0c4e04163bacffd6ed410f478dba797e3876471639f9b8eb7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/certbot@sha256:2f795751ff48ce91f283e3be2b7eccdd3c94b791495905c9051cfd7c149aa2fe |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/certbot@sha256:2d058fd490a9d8d00886cdcac5d32cacc0b20c3851734b4020d18e1ed8ca712b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/certbot@sha256:d778604ba3c36e55375e3777b8438e25625a4c6bbb48bcc294a8297f4bc1f654 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/certbot@sha256:d8388f1a3b91544a279ec62bdfc24591ac83e155a0958fc1d881be91c9e94f87 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/certbot@sha256:6e2164e02cf8d1a311775e03e0abe30b5168257bd47bc8016997fe6562918dd4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/certbot@sha256:810753f3dc277ea0b550b408ffe5869953f5b7b0741245066ec980efb5a8f540 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/certbot@sha256:5b844ee9cb33a348c182f65bbfc84e7ec678b4b1e633aeaf567cb19346980b75 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/certbot@sha256:d975eca2c81287ab9244ffcdb7e413d0d2f5a1b14b697dbe96d85eec9ea2f791 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/certbot@sha256:da627eef68ac65addca6638e7214cd9cefe5778840e10fae41ab2d2ad2d78e49 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/certbot@sha256:bbc9f61f99ac813ba3b74ba4d9143702c8b74651e678ec69a3878b261b2209ac |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/certbot@sha256:309cadc46f4f3ab2b8b32f33f4a317e794a6f05d37dbb8f15a5aa79c8ffc9b3d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/certbot@sha256:ca32aa3baa2a4e35aae539686853d5f137a3ff635e3c20111a8ad420a4422f32 |