Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:50cb8f681fc3a23956f6876256b758d1f8e3ca720f517133f92252603b526579

Manifest digest:

sha256:af5f0e8dc5023d10dffbf6b49a0740999fe0265b5612caea854299cdd5fe04da

Size

51.08 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:fdd7df63e1cd7baacf53a388e319c8f57ce2f5545ca5576fc9af0d26c6b228ed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:fe13c016e20f1f0610c6c586e654ff2ea52ebad2fb147af2637271b4f0d3616b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:02adb3e3257c7716594f429a3e93bd2387170af0e3b362e115cbe79b66c0f8e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:403b29dadc3839802f73ca3dfa70f85addfcfce95dcf88d196eb7f5fdda4420a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:9333d163f7c6f46b5a64b12f4216822786ba1e42b8c5051380039c7a73c3e9d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:7dc59ce1e885e8bd18582d61afb7ee8fc175343ca73be0dc25661915b1ef94b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:c860a145aafc931756e77157568e87b18ffa4990aef1770c87b6b29439db7a7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:c88edeff9a4f8d39ca2824ee3e75d393e9a7b9d9894bb0c13f0725360665e01c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:2f884168655e6e526c11b297d169573fa627bf019832d08c0b951956ba214163
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:f849e1cc86b53587a2faa5c513f0cc9efc327bd4634f0887d26bfa618475a3b1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:66ab61069b34a87810af5dd093a59fb6e3e64394f043636c0828271ec67e8494
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:3823a978261463c0855e095c3c080b1c1dde2c4cec1e0ff5b00cf3b838644fae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:bc6d04aaf4ff7ec7fb2eb4fda3cb147c62046fe521cb6a42fd7e5c6bed7a9019
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:2faa37a70b511b6cd7d0b19d8ca946113cafd29acfdbc9d5ae57388edda879a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:e93bb55f45b922e5a61ac241f2b45229ec287cbb050a758003888c84aacc8d2e