Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev

Index digest:

sha256:da12e880324bedebd29f77494f7c604f98f33d32d9de6637c6e831c3a942ea87

Manifest digest:

sha256:200676c4e0f7bd5a20bdc43f3a85f058f64078fd3fcb916be5ba05f8ab761510

Size

103.21 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:91fd42c76fe728fa41a9321248dbd6702e50a83636572be24d6d7165b51eb96b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:34a1e747c6e775fdb4f3c396fe11bc02b2e0f8cc7ba08112e2096f279a1bad48
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:1a79d913d3fe561111411453292fc5b757bcf4f7ab8963b20af130a48140c1d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:3e3ff1b707a869cdab71665ef3a7b546b63e591ed6ca13c9d2981a5bd5b316c0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:249abac6c794cd146c5d9817ee20e55b73d5af597ffa2af48248011f3e226d16
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:01808c346d5658142c6e665c2267d36d1f6225adb398a9c3d3e4f5c406f21d78
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:5523c8d028ac064a625da0df8b73c09e537e758e6871d95f71283ea4bf0608a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:f8d3d6f462b45f871d811fd39655343ae3720168ee45de26523052752721b6ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:eb0669850e05c1c875e4d18f875171facb5dc329264a1a28cf089a6df68cf851
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:fbad0dc4c165c38dfe67dfe9fdc360483a9cc4194a23aabeb9151f9125ab84c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:77941d6c18c3818ae0597b1476d24c0130966d0664d50f2d89f992f86e9c74b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:011f933a8c454bcf70ca93fd33c9022847911fcaf4fdf4be70d7bc783b3cbb71
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:7436d46c4a12db104d4e9cf4235a916222a6e6b694e21395aca5b5d2aea15965
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:8856a76375a5b6e44969cea350a348d3a4cdf3759a0dafa49877422e4b9249a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:94b4d81b18bb97ba5d432cf316d57dcbbb6d249bea5d449740677686557b54d5