Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x

CIS
linux/amd64
debian 13
Tags:

3.4, 3.4-debian, 3.4-debian13, 3.4.3, 3.4.3-debian, 3.4.3-debian13

Index digest:

sha256:e206d1cc339e925716c27f78176cf1d6da9101eb1ede996f624d94babedc4561

Manifest digest:

sha256:b6a5b5e22c68f673bdcebb5d7dc7e26e21693bab80e0ef04520514c6690e05e0

Size

91.39 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:e1c4d0c4ca43c83fc70f13637e895aeb5a7c67f53817b7eb0e5bc98481485509
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:cf2521ba29bfe7e4ab11d6e5bf878bd0e3974f75f0c25e469f40f0e657057b75
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:11d9dc9dac7cfd37cdd22e9b29c6dc109bbcec031e1ac27ea7e8901f16d875cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:e811f9f68f288c195d4f904ab74a903a6e1953154c10eb79e2bd8dae419087e4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:6ab873f2c9f65346a19971936be598b83c02a46c69238e6a79e2797f9b49a63e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:68d871aaad30b8cd97c7e99d6853012960b9c72473ec7fc63b60a9ea69ed161a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:80d299cfbba4f3b0ba37e69e1a22307974334c28779bcb878f2b93866bb0dfbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:f621bb9547adf21082cb5c4dc476cd877906d4f0e6d4887d72ae80baec342cdb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:2ed9c2f043ceb92a4f985db995c887673a0c7ba3bfe707f895172540cf84d3a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:c0ae282d601de6b217914abbc0a7cf09b26e07e9fbd81f22b8959819d2297080
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:399c8ef0c07511575619296492a62996ca27d0b4ca3bbfe573130f7cb1484810
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:6ca91654dae43b3978bfd70ade87ef344db92e8a7c7c3d8b9807af312f3638fe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:2614da21170ea9e9062c36cb4abeb08767b7de9d912fb2f0daad92ab2607e973
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:27df134063150e0d63436895a3afa25e643f47aa001b481ae32a1dd3101657d4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:1a80c85160a5fc2aa2abb21aa06e57de0df73760074ab28699c901f430c2ca01