Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.5-debian-dev, 1.18.5-debian13-dev, 1.18.5-dev

Index digest:

sha256:4cdcebe66a9175701309f7d86c5613a834ab729d74748112df6b209b49772664

Manifest digest:

sha256:988bab3f279d72849363a08e8aa8bc10a50488c267d038597715f8946ab1d80a

Size

51.08 MB

Last pushed

11 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:d6644b0e9071b96de0350186380baa014b3036c0648399e4d1343154c6236286
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:f089fa7c877315b3c47462cd7d1022125408bd2d74c1d7d773be3fc3bdfe619b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:e2518dd8de71b49415411bf584c05a33230fd2959cd31f78f42a4d2ed9e02ce8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:e3caeebcb4979d045e0f163946ac9e2e8440e67b5919b92172c1230aefc369a1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:bdd0f2bb5ed4aa57eb0779e7244253c52ad6af8fa6852f235a507959f3e9e7f1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:69940dee04c61d92ea428d11d4e77a7b96e198e7292d78584f782f4db6b18e75
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:0e297653a47198b06668b0c448eec7def39fb541ff6c74c28035e61bcd589fda
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:64a387ee31a2e3f1fa1136b7b4db5a289f2ce125e949db8b542b3a860531e7c0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:38db4899173ac27f2c7061489ec5d380251292ccf6cadbaa7f5e4924ee784c52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:0f55ac13e163dee0bd995b4872457458ee7d22483ec445a563143db51d721eb2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:848fe4a1c2083cc0c05e3f43f691002ce8870f3e609ec6421cb40182a75800b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:6c66b10b15852469d54023f7325681885c7506bd8806a995e5aa8f38d331406c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:67cc17322f14f5d769a9333d2f48e96d8321e59a7f50b4c856f049c1fd62ec4b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:3056f880838674a655930779d473ff94a3b1fbd97f7e687c6a931569ee4cb6c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:b28c8fd37b3a4807975114a2996b0a2ae4bbefe146020dc39ffce0aea4e7d1dd