Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.3-debian-dev, 3.4.3-debian13-dev, 3.4.3-dev

Index digest:

sha256:b037a618a055bb1a1b98930447d95a273a2312e76c6c4c10dda72191d7b98e1f

Manifest digest:

sha256:15ce7a2c67ff1e50affedc01dc7825be3337cc04b6f42ba4158a40ade3a475d5

Size

101.08 MB

Last pushed

12 hours ago

Vulnerabilities

2
4
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:39e0658d124138fe9d8f962b6a89411b754912e64803715e3ced468680f8ebf9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:6202a7b652404e2c31b8e1009846682f9ccbcbd070ebf1510559030c95a90a13
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:79a7677c96d5ba3606a5e353a5fd0bac120bd72a2ad63375a0705aa690dd267a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:76696dd3e9a30a41dd44458476d06d3fa1aa5cbdf8aa37705ee1bef9913f4187
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:54ec0e2f19f6d02c442866852c13ecf0ab49c75dfff135f3db44867952236321
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:12b6e3dc269d5e282879e365f7885a8cb6345abff11978fa998edc06e5d315e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:691e5a6d5feb146905680bddeb9200c325c85a33274305cd184757e42bee1942
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:7d751d31be3ac8b54ce9568ba3430dd8b081fa6158b29d8aa3c2f2b00d146198
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:01b80c4384cad2269b3d3621b4357060265442b08d7a0bf02ead9b71585db097
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:60fecc3cc4e8cbcff0e4aa029a5759d032eb9e5fa84ba7a916629c55301f7510
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:b49da05dc4e82968997f3d43971a62194ef70a4f83d98de988c4540d8c9fe1ab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:131f6b340bb98dfb8820db637a671212ec1571af567274ed06d4d56ff29dc835
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:6be243c1f919b5f233ba02d75478f8d318a545c7f23444c6cac6fda6a8329dfe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:f555d83d354a14913fc34ab61b12b25a12f075f2ec33152ee34b479fa7230dd7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:2bf13df8bf7cdc828455150594eae1e6d9f41f1c6d6bf8be53af96841c924e49