dhi.io/couchdb
3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.2-debian-fips, 3.5.2-debian13-fips, 3.5.2-fips
sha256:b1fabbf4d880a86f6238229a6f2cbc38e0eb78583c27292ee6aa13b0d5a4ff32
Manifest digest:sha256:ecf3911f5ac82bc00fcbcdbe8600c76d16993b5dff999cfbcd3eedfb96f022c7
Size
94.34 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/couchdb:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/couchdb:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/couchdb@sha256:c33657b4ee1048cedf345f51a0429a33a93c4d0c7a4c0f1b1ae6dcc7e58247b0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/couchdb@sha256:b6179ee35211a575c2bcb14087c29f52445ca96cb9cc75fe6565c685296e9173 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/couchdb@sha256:4e38980e7d3a29558b2362449673451777110343ad7f649380a58b3191082935 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/couchdb@sha256:54d3b273abfb80f9a31a32691463ea27c6f303b0de218daa74d1e2ccef279cc1 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/couchdb@sha256:a92a2e136833abbc506103ac81b3222a9b2cb0fafddb21645e8c60fbf140adf2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/couchdb@sha256:686faea9c034e82a3371b07609a23e6b9a7e5545c62e479a64546a04fd8b7574 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/couchdb@sha256:dbb1defb60c29017619c43a797bf1d87a34ce437e1cb20b0afd04c84c2711a4d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/couchdb@sha256:00920421658b1f7653f241decb387b4366205683ab79ba382e9e7165722f3eba |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/couchdb@sha256:5b96b29fb1ef0319a5ec09deedbe823f8c9a946cd529ef0872476dce36095bf7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/couchdb@sha256:aa5ed22de8f0cf1145929926612068c1e08b1377bcf8dcfe9bf82f2e64732893 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/couchdb@sha256:ddb7bbcbed0d5351e8253c0b33cafb079a04d4a94fc962fe883307a6b15a747a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/couchdb@sha256:4debd6eece4d0ff58b53d5b5b85547535ed05e0a3ad8f191fc8b0d3f951a06a1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/couchdb@sha256:32c42a3538e71fb1f305b277167b1fc62072cb80e2e7cbd4689ae90a85dd66b2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/couchdb@sha256:390663635fafa4868468fcd4a6e11cea7b4fd14f545b79c16bc92193ecfdbfa0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/couchdb@sha256:5694bcbefa60b4d04f4db61b19fa9d33d88c7cd1bfe89177a294193d6f360510 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/couchdb@sha256:3b5899c68cc3fc317353ac8d16988b917e1470e3535cd9a8e66cfdfb6b4540ee |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/couchdb@sha256:0572a02b25327e9393db784e29ae50252395d8c3c0e0571e2452687321f9bbe9 |