Sign inSign up
ChartMuseum

dhi.io/chartmuseum

ChartMuseum 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.16-alpine-fips-dev, 0.16-alpine3.24-fips-dev, 0.16.6-alpine-fips-dev, 0.16.6-alpine3.24-fips-dev

Index digest:

sha256:17f23e2770c5da81b5f4e3611165dfbe7e77866a33bd96849291025022c242c3

Manifest digest:

sha256:45e6ff969cda2a3fa4001ce529b3015335ad54f3d1f1ccbe11575d5e12c7e6cd

Size

23.86 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/chartmuseum:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/chartmuseum:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/chartmuseum@sha256:da4345f9147ca63bcf0fbd3779546c9a2c9f7569c1582d508568870a62ee6463
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/chartmuseum@sha256:e4c311e30631b6263826ddbe2885ae8023f680867cdefcb2e10f276967903e4a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/chartmuseum@sha256:049338d4746a81a1695f8d563edf57f5cdde581fbf3ac1e00cd919f780052068
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/chartmuseum@sha256:87e5b5d6222260da478ef5c5e78daf0f6214b5f9083b9cb61b8bce183c707657
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/chartmuseum@sha256:773ca30107babb51d8554fc73bea9a16c08d47e3e8914aa70873ee1a20cd0df2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/chartmuseum@sha256:dfc8089197fe4207105ae7b9e6df18caad99671e3993f5c7bb2d4d4a45715f92
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/chartmuseum@sha256:e3180603ab81763ba177d2507cbd6f75afa2dd22d32b93523ee2770d88427bd8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/chartmuseum@sha256:79d4da80f0490a3c91b4f8fd539b8f69167d9f224b99f048c0e0f5129a4bf98e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/chartmuseum@sha256:732796529bc793f1cf3d31b54dcc9746d9d09c9abdaeebd404cc82cb69b7f828
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/chartmuseum@sha256:490f71fec3e6d33026df0d367970ffda3c624a6653442472caef80429ce8b077
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/chartmuseum@sha256:2725fe43f892c18e2b9f743229db313cc91dc965f65f6d11ace1a5b6ac2a4fe9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/chartmuseum@sha256:14caa805dec91c211edb920ae9917baf6894d97a563069d3fdbd48c2f9fa5a43
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/chartmuseum@sha256:00bac992d2b9b6926543782044784397438b7a1836b8c25075630909fb1b1e7c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/chartmuseum@sha256:f685930fbd49f86d1fa644a65d57ded18bc911cfd0845ea64e9e23add91ba958
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/chartmuseum@sha256:6cae4686714f780d03bd65459a636e10f428404bd0360126699e068370028be0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/chartmuseum@sha256:7458248c9cec7bed3a928e539802ff1a2c131313f8df0cc00a6223e25e9fcd40
SPDX SBOMhttps://spdx.dev/Documentdhi.io/chartmuseum@sha256:4877f9099dd81cb220a0c6ae48e927b3c8b764e5df46b7d6646445576fda8602