Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.5-debian-fips, 1.18.5-debian13-fips, 1.18.5-fips

Index digest:

sha256:59b126027acd237a9303205fcf6cd85fde81b840e1c740e4b82e1bb97ddfaf53

Manifest digest:

sha256:dbc04088023a3d56b4fa5c2a5e23f6de111ef95f7c112be853d411924c93f128

Size

22.70 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:002577554a2733338646d4b5902b8b2982c7be0c520b1d7c97ef190a7ba85d52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:57aef234ee3c38652370b6c03e1f6bbdf77e532db894c93d95ba8119866276fd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-operator@sha256:c63b3fe7c96d0815055352942b0447c2e4ffc6125b3e87fcb9353024ff626070
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:f7c9f1dfd6c4a9fe25092154ef739a2b65551f650096010e1e970ed55ef5936c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-operator@sha256:98344b956ca588be0a9692db07744982ee3265b3b7806cc2ee288813059e6017
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:007d4c89986a5fcd2f5b4ed776a1d6cbc75d39119bb89b59405fb72c34f78bf7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:c098fa5a90b7fbd0a5be95e1dfc5584f03623129cdd6092fcc99920f15aa66c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:ed4f8c527a32ce050122db102f595453105f60260da1a861d1f93dc9f49413eb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:740daea294b32623d82765285609c7da8b4956eb4387a5f845c35f3bc6cb13c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:0a3898241f78f526f053cad4e889204d7e27e52e57ec9487b562b8bf73e17d77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:6d89689d6395a31eebdab376b07ce4ae685f20d6fd12a73e409573a6808c9ac4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:d526cf20a70f0e65281da05c0ea3bb20595cc50c6c359a4307cf47f3ed3655a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:2146cd03f3bddaed9c4c3118618e03dcc4f0bcf4ea44bf964e81388b1ca23a19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:5b13771e7a8c8e4d98e72c4c0e7c837da6240bcff9851bd91e2ac3894b69a9a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:ade3eafa8f1c5e728eb59d43033ecb9778b7faa906e3df4f5f98891a653d2fda
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:af1cc9a3691b03e679f05b0d5567ef5e82d84dfa7ea69df8adfcde56566707fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:57a8b1c94150a7dab73fd8b965edfa59dcdd8747e3e1bfd6f81c3a420de8e8ff