Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:af99d659a02cce08903bcef56608489ec6f673f6a7451046b35d4ea47a7ac554

Manifest digest:

sha256:86635ab53aa495e0cb38a260871b2dd63aaa23849ee2aadaa6578fef9a0f1591

Size

51.08 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:9dafb3e2d5f51c495e9a240690ce054c7558b94a7095b8954a09ab7caa0be835
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:7e23a406feac64f07eabee9089aaf4986fcbda998fc76869216f1bc218bfea6a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:48cd9b1bba46c510157f54af938c6f17456ca0c70824342643fc6c8fd70907b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:91db428de1bce090f58e51952218c39bda35b8408270f17be467e482b2b24268
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:f926c0fb2769fad95d12ab526055180df2631b4f4be5532db61f3d2f10bf54bc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:3586978a52d01bed7a34f43d0c14030cc5d10d21a127901d342ec2429510f35b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:b391d62cd4446f7d84adf55913cc8e1eba5949b834dad0d42cf4173d16dbe5ba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:431b0938b414b0fff66b5df613a693700ae1c850fd56de435f8e007abfe62401
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:e3a9537dcbaa52305823672cfbb3761bec036768b53c379421ac75b779fddaf3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:64a57074abad9ba3011c44b23416ed3cc25d8c455e28ad0833c0ec3da6ac76fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:37e3ffaf30592c9de632ec9a85d2581e422b3c6b3045841ecb5c5562f3d4df96
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:dd30c38e303999b0a3351faf6b4cb1c78b620eeb9aad2cfd294545bb7d34ca25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:fc79015d890ee284878f3ef1f888c483ccffa655895b69e7669341c1fc430f5f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:5b25e19cee8fc90c6db0f8af2b4a6def831b455aa32eb6c2883bff1807984477
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:d9ff39048821144f729d832cd755a1d1d98664f662f40b246835455bedfb3c84