Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev

Index digest:

sha256:f260b1755dc4648003ce302af0247067d11fef3fdc7225f47b2e8962eee3472f

Manifest digest:

sha256:6dc4e5020cd942803b4701f02b3af14d713e7bd2846e8bde7763aa6f1a8b8f6f

Size

103.22 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:5b8df6b0b7319510dbca49c9ff9ff337df02a441e40056baed024159e978b863
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:3f86aae275c17faed4b973052c9f02b9d27bcace2b392adc0c1e5739f7fb3eb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:6a152d49f4f1c39153e04bb272780e0432ff9bd446329785581598c9ade276d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:184cf45689d2b3579dc2d8c4a7fa46106689f13bb36b51944c227f4410eaaf5b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:5104aacf7d25a2d3f0f067e08c270a84621943e6c423fc7b7823913fc319f4b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:6065778c53d00b5c4f3c3ec5cc6374fae1dfa5a1e742c49987f6ccd108c8c57c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:183cc746e405812d3644f147ef5a1911751c058d00872c467e89f9fe56beb9ba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:dc73c912501a88595ba256dbe50c2a26ef5c010d64d46581f0113a080b05e0ff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:ddbe78689f5d417e360720086e9a5d248c8ac00b748515fdcc41bea087a9e226
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:4efe890c2b4bebd9194793c075a878bd667a380be0273d70da0efc4d29ca0293
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:f386e579c2c229233177f27a6249253b32fa4f5cab7b313695b0f17bec201b43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:7825da30a871833d11ba9cff1c797e8c5649785c8b6cd7c4c5115995b22b344b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:171db605bbaf101e8f9db0e09bd214593f91f26204cdac2f60142fd7e357f48e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:872d6d5d037ab38aa111ed1ffebe9bc79ccb10cd708d46714b1602b343ad961a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:ff7e13964356da9002c5365c90d2e7dff34461d31907d0d7343c153838ceaf98