Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.3-debian-dev, 3.4.3-debian13-dev, 3.4.3-dev

Index digest:

sha256:f87b60320c296b9f78a06a782a14ac899d0667b46d6f65cbe4bb2101779924b7

Manifest digest:

sha256:dab3db12e5d9c698ef3ad1b0b4da11f6d4c7ba4d1792b4305b4fee19d0d1dad6

Size

101.06 MB

Last pushed

1 hour ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:e8a8cd18afe5aae441b92038ad31a68ef0a8cfde97e88d4a74787022dc542034
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:43764c148e5938a08f80749da479442fc3c3607415d130f27347898b8bc15660
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:b594eb3854b3673652a98d52794e8cb84792c8941cb0a55089b8d0d89154492c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:2860baddb9b22f45c3fe5de30d3f2fff75c182a585075dfe27a20893bda783b4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:a7fe0ed707ead2123b110f20b31cb97025a3cdc5094a3aa0ead110ab32117900
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:3fa91364569debe8105b86318ab4094925525b1cece2bb8ad6a52daf762f94be
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:b3b00fe92a9dd4abf47014907d0de187cd30965c253a2354cdb24207e738f05c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:f887f282ac9871f6f9db240c2b03ee7ae7c547c347b445b9e92eec9a187bab7e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:7771dac6f2ec24930b6d395841133bf623e55e97240fb0fc8aa3f7aab2157a5d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:14d8a71ac9891d7cb852147d9d49f3bda1b805a5d405874e1e4906522f856184
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:4283b4e28c5670ec25e6c26b87143331c6a694529aac08169d5e646308f72f01
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:93ea670f0c7491343c7e8bde3ffc11396b65ba8996f73d6fbcfb9c8e34c4f59d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:3bc164eae1cf64ebe867720486d28e6a64fd0be9d908d4e93bdeadc5043a7893
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:ed3b1080e86200134a3a1ecec3991ba5176991dcea9c1d260ccb9411cf58acfe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:e587006cc57fc57f9c1209df510a9b21a868b628e0231bc9332f89d5b847de4a