Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:c4da2d11499660a2bc4c09887ae48580eb2f9f8c7d8ed6bdd6961fbc47cd9ba8

Manifest digest:

sha256:584d39ea5844d1f56ae2ec2f0f483d0ac685f18f45ba8a809ff3440dd21c060f

Size

51.08 MB

Last pushed

13 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:e69c926847888c60cfd10531398bcfc49706631567831692f09ee21b33fc2693
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:26a6ed8ae1a7db047ce0def348c0b59c578fb8a7af7b7b0f5cbaf9a60577e875
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:d90d05bb106ea0bbac9166d2cf9d8219507540f300dd2f7a2bdf69ddf62d874e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:efa5eadfea48fead64988181a4304fb38409299d5bd611df95ff54fc3ce4488c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:b51d8b3423df6dc9c06e012451624fe42b0ed693130c75ed180465e0e18f23b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:dcecbb33da9614db3bb86d5d66dfdbfa6f8ccb569c7d050624a338746ec6d805
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:f0c54515a9e035a0bccd4f3c3ae5aa6fb0f434a0396bcba184dc1dc75638719d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:c7212c798f40009cfe5e0e1084013a7d8779ed66f8c54ea1e5e018d2db717593
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:8dea5db1730bb88fbb1fee12a68912719c85adc7f97f74975d97834af2cbb8d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:c00adbe3a9a9031d88c97be8558e3d1aac316bed0ef2c3197e1e567f41623996
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:36ee8abc61414a96beec7a909ddabfc6071ac8e2dd58ad63719256b6e63d97b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:6761a4f0fdb2dc9578706ead35aad6eb9423d147d6de6b18f8a60c26ee23c5ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:0e846800988371d1dd0362579b1e9bfd6a66b6c35254ff688286478bb072e3ee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:be997a11ace5b16d3b8db5fb5db645461aa30916d208009312a3f34b5f8bd850
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:4906180f407b155805a8995a25022b17cca98f2089a0d2956d5d632bdcbb1a1e