dhi.io/dapr-operator
1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev
sha256:50cb8f681fc3a23956f6876256b758d1f8e3ca720f517133f92252603b526579
Manifest digest:sha256:af5f0e8dc5023d10dffbf6b49a0740999fe0265b5612caea854299cdd5fe04da
Size
51.08 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-operator:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-operator@sha256:fdd7df63e1cd7baacf53a388e319c8f57ce2f5545ca5576fc9af0d26c6b228ed |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-operator@sha256:fe13c016e20f1f0610c6c586e654ff2ea52ebad2fb147af2637271b4f0d3616b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-operator@sha256:02adb3e3257c7716594f429a3e93bd2387170af0e3b362e115cbe79b66c0f8e7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-operator@sha256:403b29dadc3839802f73ca3dfa70f85addfcfce95dcf88d196eb7f5fdda4420a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-operator@sha256:9333d163f7c6f46b5a64b12f4216822786ba1e42b8c5051380039c7a73c3e9d5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-operator@sha256:7dc59ce1e885e8bd18582d61afb7ee8fc175343ca73be0dc25661915b1ef94b0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-operator@sha256:c860a145aafc931756e77157568e87b18ffa4990aef1770c87b6b29439db7a7a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-operator@sha256:c88edeff9a4f8d39ca2824ee3e75d393e9a7b9d9894bb0c13f0725360665e01c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-operator@sha256:2f884168655e6e526c11b297d169573fa627bf019832d08c0b951956ba214163 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-operator@sha256:f849e1cc86b53587a2faa5c513f0cc9efc327bd4634f0887d26bfa618475a3b1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-operator@sha256:66ab61069b34a87810af5dd093a59fb6e3e64394f043636c0828271ec67e8494 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-operator@sha256:3823a978261463c0855e095c3c080b1c1dde2c4cec1e0ff5b00cf3b838644fae |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-operator@sha256:bc6d04aaf4ff7ec7fb2eb4fda3cb147c62046fe521cb6a42fd7e5c6bed7a9019 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-operator@sha256:2faa37a70b511b6cd7d0b19d8ca946113cafd29acfdbc9d5ae57388edda879a1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-operator@sha256:e93bb55f45b922e5a61ac241f2b45229ec287cbb050a758003888c84aacc8d2e |