Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.3-debian-dev, 3.4.3-debian13-dev, 3.4.3-dev

Index digest:

sha256:7af141a2268195cfae426f2ccabebded1ea29f71f78f7b26f0e8c2fb590c15c8

Manifest digest:

sha256:e5dc5f21d708a1dc732d1ec97ecfb0595f1b4821b7d61b73aed850f65a5df041

Size

101.04 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:394bd98dabc7778cb7b69eb41d73e13a50863d97dc4f88713d82cbbc355e0954
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:7ad1208c978dcf23202ef73d2a8d1975a976c9678222dd1cfb99298e0e476c5f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:3ec1ab4f68dbfde32d41417b3859097638d9770ae80e9ca244e8b0bc3a0a069a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:b50240ed4e1f0e29987971fdc5d6dc96a0c3b17222cb9a6ffb2d53d74979522c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:9e1c085aa4f2a1130921c1b3168c408887ac023d4895ba90e67428558adf210a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:d1ed4ea856bce96ff3fce36a21117f52bbedd7a9de61246962393fb273f4e68c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:893162cc5cb2e74a1090bb3c9ab2ef0e544d3265a36d7bedc64e4d9fe21f47ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:9df215f9d9bfab60428e746ff95245d88002e92d42ccb9d846631bf9412a28dd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:7a687fb6bf0091cb5ab23df799ed25fe1987994f15fa23ba8ad57d0ee7f90be1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:8164a375bb596e73d549c9e87f859dd10a94e1514bdcdd93e082d4a1f54fce00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:7b34608cdf3da69cb0bf6e8209bb6e82224c466387755eeffa6cb2a25ecd8dcb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:147f4f05615d340968057aa954dbf593bd2bdc46695ccaa3b73e629a199a6077
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:56d5f7455840d961312c54c33405367f9e8efca2c8c1a2832e54e1b87c31f96b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:d03c4bfdbba8e617ec3128fc48763d6a0dcaa6a97b9cc8f717071cf7cb91829e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:e23094ef6d5244f5a25627d9dfa24ddcebf21de64280b00e22212db854023bc4