dhi.io/couchdb
3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev
sha256:704db80082b75ee7bf77b1d040f382ba5f454de9252a79bc315073b0d37d1456
Manifest digest:sha256:b5d40f3527bbfed57c73cbd286fc55195b9ee6436f875851bce46d404e00bfc4
Size
103.19 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/couchdb:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/couchdb@sha256:e4ae96c8d3cd25944efef2cdd10d3a8f356e9d17340c8ffb949c05cf38add673 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/couchdb@sha256:d49ca74ee13ff21ed4222062c77999462e40a7180077206aa7629ed09b967025 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/couchdb@sha256:3b2752aa69e39e47cd645e99851476e7ed06bc0ba1699f68c9faf7f151977952 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/couchdb@sha256:34eabc41f2876d7ec7db2745808ccc35ccaf79a28fb3b4d1e2dd5472f4a84291 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/couchdb@sha256:e7ec23e64de11db4e6337a39d694511190b7231aa7e4dcebd74bdbca666e9c56 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/couchdb@sha256:add0783712d4582944f83b405b62dcab68cfc056da04c6e67471e45af1f7402b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/couchdb@sha256:e126d7e84f3464b035d95fa95423c01b77ff2da6bb58444bae5f0ea487b93366 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/couchdb@sha256:ccb649f2bcc966df0483076e5d3cc00550f83d1ced7349cb131ca408b5ca70e6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/couchdb@sha256:0b266919b79b2d43c0e8f7e52d605c90dee259a742713d2870ca49ba992afa01 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/couchdb@sha256:dbdd0d4addf47b5094d20d5211aa7628d876f38e72f175252cd6c08a67c22a11 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/couchdb@sha256:da8926154f000716537b37acfd4aff4eaed6dcf29de800164f8ea31069dd0dd2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/couchdb@sha256:1c6db44a7ee83f3baeea9c16c3b200233136ff95f6692c63426af65ac1754bea |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/couchdb@sha256:c77bc5594ded7b6f5f25bf5bd23bc5966efb643cdebae3501405c8acb8487738 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/couchdb@sha256:16ee27dbd6974fe35b78780c3c172de340d268160fbb2a7d28f30ff3669d0d61 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/couchdb@sha256:da3b948ab4bcb5011f7d5c816fa2ed512b3965489f83767066d68d69b2cd484a |