Sign inSign up
ChartMuseum

dhi.io/chartmuseum

ChartMuseum 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.16-debian-dev, 0.16-debian13-dev, 0.16-dev, 0.16.6-debian-dev, 0.16.6-debian13-dev, 0.16.6-dev

Index digest:

sha256:a02ab07c786dbdd2eda9710ca7fbe7c3a6ed865c6b68add67734136715bb9fa5

Manifest digest:

sha256:279e7a64e5ec5f60166de208af7bf7e1c664dedf2f6a5a0f567079a321720d73

Size

42.44 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/chartmuseum:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/chartmuseum:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/chartmuseum@sha256:57b70ca2fc46af91a912e8b6ce3bd010da30ef5b52528ca71eb29f07e3ed3835
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/chartmuseum@sha256:d70f518fe037d375f5d194911f22f001d026fba9291318b83f77804c8c11e49b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/chartmuseum@sha256:981433e85c73da1d9051fd869ccf4310329877425a1138f257f54d40e1b634c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/chartmuseum@sha256:99552e36f4f501cc3df2bdcd3e3a1a769c022953077692005e4cacb16dbf5d3d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/chartmuseum@sha256:b28a448ecd902e21540d542cb430a33233a9575a003410cd6ec6b7950b48cf5e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/chartmuseum@sha256:2414b473cc2a91a55b21408825d8b8b45de8045b3a903f953ad8ce42c95001a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/chartmuseum@sha256:997d3146182fa59f0a7d996ce716b2a8f21e2045c3d55f4a871257b79b6f9aaf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/chartmuseum@sha256:b8144273d3fd644644b680f79f823c94e9d2d2b050a93de10c8ee4a0bc60e94c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/chartmuseum@sha256:2041b8fe541c81bec532594e88560c9c79a95577b895d553ecb05a8e77bd7d49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/chartmuseum@sha256:f16f484014bb65467ab50b51c5274d4b822466b6668884f63c85c4614a3fd378
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/chartmuseum@sha256:84a7b6319bcd736367968a3e745450a38b9fcdbfc777d166c293218f4f13ef37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/chartmuseum@sha256:296027b6e34db765005301cec5871c3f557f25dd5fc585ab39159aa999d739e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/chartmuseum@sha256:fbc67a019e6601479b76a31d5f153bcd05b818cca6de8117910d224e916446de
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/chartmuseum@sha256:443d586134b5642444306e48db95a13e39e067e48b4c30158102e7b48d08a1a6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/chartmuseum@sha256:e043e291c3e9527c06221d9a5726275bdd4d108c89dde35d03cadf559af1b3c8