Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.3-debian-dev, 3.4.3-debian13-dev, 3.4.3-dev

Index digest:

sha256:bbd99b0ae983d1061b4dd8b41eb8f7ff620d1ad319337f41a69758171b7f93f4

Manifest digest:

sha256:1be3c2f59f0f885810d5a29647e90d951eccd6ac5c23b30b02a96dfeb77295c3

Size

101.06 MB

Last pushed

19 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:0b68bb9c13ab28565073836a3d027418e1a2d9c97cba58adf554c41924fddd0c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:9fcd931923ca09ff7f3be460fb82ae42990d9e0fdbe5549c5f8b8918f65171ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:8e6ea926a4f2da44ef7a4573748f18edc00bd98871ed4e17bf49927f594aa1b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:2ea8d7a41089acae9fa8a86a0d34d0bc75d9bee1eb01e710647c6b68bdae98ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:1e3a0f17c7e19bc340d952addbf3c468bdcf77e08a9aa9effc3ef79b5ba23ed5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:82c6dcfa7850519be4658c0f00c693cbfb8951cb57d8ada247eac56dba122ece
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:133d177d3bf02ab1c2a4a7cd45d888715bdafe4b8439506fec9fa6c790e66f72
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:007798a2f32ad27cb9ed7d399fa345aebe2df4858db5fc0a07abbd016979a7a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:e63ee201095fb6ca8d31e7c32e70162f08a6e92daaf3e57f72065d527ea20cbc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:ab852ded3c050f9a789558ff190f0a3ae46decef3328c8ca90d3b0c58ab96547
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:e60b23e61325cf3f455815ba31c6f987870b99ce724080cfba1dbe7e4810c7d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:54e0cf40a80c650fd323d7e3c30b2c4a9f7acb4e1189bf69efa2ccbaacc183fd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:958cbe1d9427995a986b73fab93d0c513a8f26615d0d63492642f214f6163c32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:298a658fe3a0d762eaedc08eda1663247967ea54d612586445058d6698800d2d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:2ff26a2858a88ccce6f5d4c422d13329da4d30f701e2e526f9ca1b3dc6fffbbd