Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.5-debian-dev, 3.5-debian13-dev, 3.5-dev, 3.5.2-debian-dev, 3.5.2-debian13-dev, 3.5.2-dev

Index digest:

sha256:d9b1c10e0fd2b5686496f4405ab3c1480dfbef2c0d93c6dc4afff976ef3d9e7c

Manifest digest:

sha256:d892e110c019cad6dca792a271d9c0ecb8c4ad0b2863b9682e4b4354e3b514db

Size

103.20 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:d21c1c9e0bb7d5614fede8927de1f4bc79700432db244018415b11fca89f9537
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:bc45f6c1e32ff6e1ceaa2bc0bd74e558a7e04743211cd375ac0587a19d02203e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:3abc71e2f02a5e0bc960286c98e664b5a075c87c57ffa37e7f1012ae5d2728e0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:2ad4eed6b150c5cbc07722c3f93b5d8a5eccaca7e60e9ec896e5c29eac819221
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:62b4dd79040b964dd71f99ee54211d2e52a2bb9858883495ad98391d35472e20
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:20d71e43528eb28c31c3f2673d2980982476783391322fc348209570f9a5efaa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:40b4b74155f7b6f0c112ba9c6e51034528e91625260dacb4d7ee533573ab5c55
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:a039c89f173ffcc7f67926c289ab322a9aa18414af8bdf8d85bef28c72a30a80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:27fee1d0b110969b3f36de3709afbfbdc4d538ad85cac660cfd0c60c828bffc2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:67beda1bec7212f2f8a09aba681f37d976b2cde78c22cf251a5d362a489451ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:926b4f0415feac5a0f6ebc67f3f6f8cae015f185e9f3f76426d347a82df7dc91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:bccd3cf16384ea545b677c7749288406477f11b995a1c278b7cb39c6cdf44c48
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:f982af9d94f461f203bf66c0fd6bea8c8732b33f0ceacb57b459df2cb842e1c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:2d0af9dea77a93ab348fd6b7a4bf6d8468c049eb3b02b61b1ed777169af62953
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:d1a132213cba895006360c3505cdf6953b178b119ee692c41a80dc47b3243cb7