Sign inSign up
ClickHouse Operator

dhi.io/clickhouse-operator

clickhouse-operator 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.27-debian-dev, 0.27-debian13-dev, 0.27-dev, 0.27.4-debian-dev, 0.27.4-debian13-dev, 0.27.4-dev

Index digest:

sha256:f9e943487960d7798d8f0bfbe9efbb8f11cb8da0671839b06ba8a173d10039ce

Manifest digest:

sha256:cc1c95298b4928bcb228ab7301c781a4fcd1d0981c519a7999e00d94c9b44f19

Size

50.84 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
1
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clickhouse-operator:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clickhouse-operator:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clickhouse-operator@sha256:dff1bf8fe44f5181c5f55d4b48a6db3df318906111c7dec5be42b46b9f1df997
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clickhouse-operator@sha256:fd9364c3216b15c661cb3d69c11a7b1de79b84647a24a6e04616fb34dfd72883
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clickhouse-operator@sha256:cad127041986977253ba72ef0be75e3ce2d8da98ac4d8954d51887fd761fdb9d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clickhouse-operator@sha256:26906dcba23acf934b6d99c178e9e59e65d453fd7efbce3da18888fdbd9019de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clickhouse-operator@sha256:eb2a08802838bf70ee91abcabfd6fc887ff614c08642f0727de1c01ce6e6c12a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clickhouse-operator@sha256:8a259c646b14076dfaeac636d49d147a4aeeed868e260952b244f257f8e42a94
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clickhouse-operator@sha256:7b523a4348516f683b65cfcdd3edfed4d9e9156db00930c44d2c10e320aa4c1f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clickhouse-operator@sha256:36ff8ecb453f8ff7a7f2609b0c159c989d50552bc9849d10c38961dedd0f84ca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clickhouse-operator@sha256:7e2cc1ed5792cec59fc021f94f12e36bf07c6803d8e23ce35898b8cbc2128040
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clickhouse-operator@sha256:595a83c1663fd594dd010bf514b23dcdec7dc2456ec1841aba5431e59425274d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clickhouse-operator@sha256:e9c7820438f5f5a0f098a4bdee4f4e17e8fc244afaad036220d99d4cfaece667
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clickhouse-operator@sha256:6ed6d1f51e415845b46b70d09cf63b2871f66c5335d5aa399162faa28de8b758
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clickhouse-operator@sha256:1062eda9e9eb90dbed5f0bb3573374be721b5d1787a45d73edd0eaf37d5ad693
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clickhouse-operator@sha256:28eaf25c538f672460c97e46ff3f4802daf4740047105e94563693adc43ae919
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clickhouse-operator@sha256:36989bc675cc515fe367c86302038a54c99e7160da16da94c8b00f7c356bc65c