Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.5-debian-dev, 1.18.5-debian13-dev, 1.18.5-dev

Index digest:

sha256:e6d9f2963096d2f789904affb7774cd358dc7fb64122605d4ae6ac560cf32cf2

Manifest digest:

sha256:e2ead1a6a307b137108fc07d3a5aaa6fd9747c82b1b009f1d11ebbf76deb7cec

Size

129.65 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:91e8b6598c2d66be26ff15ae83c2b8b0c63fad9b0d752c07ba05aa6f82adb1cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:00a62de8b87de185a7016b934704ffdfc8b99f85bccb77f3007cda8512a79776
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:42b5dadc704b2523e5029dd752eba49da6e5e29406c8ace15249b53847dbf47c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:ca8ed6ff8d987b8bd9268a22fcec37fbcb42160e4e81524dbd862d469451fd12
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:c2536f62cc5456325f38f02f56e9ea3fa79c86d4ad837bfe7c7a895cfb2dad3f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:735225db812441418e4e6c348ede05a493bf6487d912eb27d1d550fa753f1080
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:a7c3ae9e172388a460e56ef6d6c6f7f9f7d0766cf608063968ebd4b48600a30c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:94231d4fb88e2030e1df343c19cbb33bb2c84e97a10fbdf5f1c5a7faa37017fa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:2007a9d0cb0d979c889d42ab940d3f16899b5483a2fccf9d2dbbba8d6ed16499
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:202df668468f469384dc86fbfab37ace7536e415490f71b1bf76bf6aab304d2a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:950c46b3a34c8042f89e7d0f4b123ad18f55bff2f9478193181dd78808d5f57c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:48eb85662cccf8edd9a439b74daceb081accf7a9c5544b5b87d4ac224715eb38
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:0e705110ac36487eae6468fc8905c34b1f56e055e86596030c34ed9ee1064930
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:86a3796e91d0b311de6454dbb32059e6687a23202be60dba829bf97ac62b5c6b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:491297ef6c57a4e93cd1a3907cd7ff067bbdfb0e3a6fd2cc968195cdd239ea14