Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev

Index digest:

sha256:704db80082b75ee7bf77b1d040f382ba5f454de9252a79bc315073b0d37d1456

Manifest digest:

sha256:b5d40f3527bbfed57c73cbd286fc55195b9ee6436f875851bce46d404e00bfc4

Size

103.19 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:e4ae96c8d3cd25944efef2cdd10d3a8f356e9d17340c8ffb949c05cf38add673
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:d49ca74ee13ff21ed4222062c77999462e40a7180077206aa7629ed09b967025
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:3b2752aa69e39e47cd645e99851476e7ed06bc0ba1699f68c9faf7f151977952
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:34eabc41f2876d7ec7db2745808ccc35ccaf79a28fb3b4d1e2dd5472f4a84291
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:e7ec23e64de11db4e6337a39d694511190b7231aa7e4dcebd74bdbca666e9c56
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:add0783712d4582944f83b405b62dcab68cfc056da04c6e67471e45af1f7402b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:e126d7e84f3464b035d95fa95423c01b77ff2da6bb58444bae5f0ea487b93366
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:ccb649f2bcc966df0483076e5d3cc00550f83d1ced7349cb131ca408b5ca70e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:0b266919b79b2d43c0e8f7e52d605c90dee259a742713d2870ca49ba992afa01
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:dbdd0d4addf47b5094d20d5211aa7628d876f38e72f175252cd6c08a67c22a11
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:da8926154f000716537b37acfd4aff4eaed6dcf29de800164f8ea31069dd0dd2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:1c6db44a7ee83f3baeea9c16c3b200233136ff95f6692c63426af65ac1754bea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:c77bc5594ded7b6f5f25bf5bd23bc5966efb643cdebae3501405c8acb8487738
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:16ee27dbd6974fe35b78780c3c172de340d268160fbb2a7d28f30ff3669d0d61
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:da3b948ab4bcb5011f7d5c816fa2ed512b3965489f83767066d68d69b2cd484a