Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:511d43c08229719e34d97fb0dacd39cad3417bbdaa5f98cbe6ec9f06e549e84c

Manifest digest:

sha256:6991bfaac9ab60b0644d8753117f5a230896c94949225c04f8fa2428969e5e25

Size

51.08 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:c007d88399ca09b8c02a53d38ee8ccc20dd431becc371c4a678395e1fa6d0a12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:63164b0ab494150d2c441443d5e076d49d39d81f32040abd8b72e9d2c917fbf3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:4276dd7c87902fc2d445919ba6acf7fff173a3f688917d4e64595206b7087c8a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:85f5daff3ac7ed86d908c121475ae8a96b109d7cbdbe4f22190993c853c88f26
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:cd2edc83a5c23c1c08261420486bddc814241c3a770d3ce7207cfac81fd164e6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:4f4234a481fd88455e1d11079a6ad12cb00d1be7bd3d643e6cd6b034f685d616
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:d4814620e6e176eb188e58382f1b89552b0aadc4c079ba81027d4217c413227b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:b7101e36f0ccf8378af6ea95bcb5adc602aac7de8c89427bc512194f795d09e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:5683645c8e07c51e7add25f42e4797ef0c8ff14935ce67f0ccdb95e026f0ed06
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:8315b9179e6602063362b02014b44e8e563cfac421cd5b88727357dc129bcffa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:61a15ef693fe80441786e2632a2c03a707c5ee621543c130ef56ddd95044bfa3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:5bb7737eeb5316a7a0cde68efabe74f84a2deb06804c998a18e584042096a242
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:279e298fd0edb7c63f6bb7da6d40114e953851bc4fb216e32da94e8af254a816
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:b1d865eee72ef60b770e2452663dfce178b3330039d13693dbf400e0773f63c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:e56398331ca17f8f2c1722979306441f989a5250484ef8239d9a1fb1ef13bdda