dhi.io/chartmuseum
0-debian-fips, 0-debian13-fips, 0-fips, 0.16-debian-fips, 0.16-debian13-fips, 0.16-fips, 0.16.6-debian-fips, 0.16.6-debian13-fips, 0.16.6-fips
sha256:52f51c2797e449295f6be1ba5730b31dd0f2f89816f9966679f9fea5903d2757
Manifest digest:sha256:994ea23c37b014652f84b1ea4b9ac10dfda75c7a183e0f1be7d7aa2549c7d5bf
Size
28.10 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/chartmuseum:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/chartmuseum:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/chartmuseum@sha256:afc726255edff5be452888e7f930da889c71fccfd353bb84bebb26a45f6037c1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/chartmuseum@sha256:1a4800c0e80fe8adb9edf030b6013f15167a26f0674e88e9cc45620aa6391eb7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/chartmuseum@sha256:702a4583c2f6d1560154f2da4f6261b7d3555ed700bca6c99748f04dd7cad5ad |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/chartmuseum@sha256:6fe217d7c5ff289e1fb6e97374632a2147ea3ec14540e567d2dfd6ed9961806b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/chartmuseum@sha256:329ca8d6f124963e3ce5e1a6672e0bcb4792d0e44a24e08a3f48017d495efc95 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/chartmuseum@sha256:e362617e8f3960e922e7b8f4ebe0abb2a40e84461ae74728303adaa09e54dc9a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/chartmuseum@sha256:e9999a9121a45b2c1258f041182b0f9b20d7cda05bc5916d6cfca913764c2459 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/chartmuseum@sha256:0c1bc6ae37b7dc7ca16a809b611e5793d1dd1b05d9f8cfa85b02c6cad04fa048 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/chartmuseum@sha256:2ea48e2f5bf95e7002ce3ebbcfe0ea61e1c68fe58fbaad6e319de35aef6dfed7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/chartmuseum@sha256:f084c6baff327f67ed70fbdc7a32662a08318b3733d119870898a6f21531d3aa |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/chartmuseum@sha256:0f8c5f51037c7fc0fd4d7a7677ae7e6d5f71808f4897fa481e0fab7c98b48c98 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/chartmuseum@sha256:84958d2b662bdc1e466ea1bea1cee0e0e0fff90668185ee0c84025bad609b8fb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/chartmuseum@sha256:488757384128753eb544d53b20a4d3d86c06e69447c259889b0ef58bf4b3fa21 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/chartmuseum@sha256:c1391fd46c4b1b762a2d2a697f126cc718bbe492a21778db6fa804ba27c49847 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/chartmuseum@sha256:f833f8f0bbb3ed6583647c4cf852e2123cc24a2f5522d1b2d786da3a37dcf7c8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/chartmuseum@sha256:253f107f248ee2f3861b05c610ff2e5b255ecbc87ae37501b2d9eeb2f114f8ce |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/chartmuseum@sha256:397f125b5e3c3170b424d6a3b23e6764cf42aa7f3fd34d3435d003a306e62133 |