Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.18, 1.18-debian, 1.18-debian13, 1.18.4, 1.18.4-debian, 1.18.4-debian13

Index digest:

sha256:b762ab12da6bb1910497fde46ad9ea15b7e9405105aa970ec2391246423edbd3

Manifest digest:

sha256:cd1c2e7a94e651a98d6cd812edb260176baddf85df26f3074b67061e91e68d87

Size

14.52 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:72b3c563e8f28cec244778c5213b62c50bbb83ab9bbf32966482c61401b3c7e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:54a1c6ef7cc49743730ca812d59e448d7d093a8453e84871189e3f7b42bd87dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:6eeb3cbe12f6d69d9133b233e33e3e35cb50ad3be47ba4f5b62e1e90951c6679
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:1391fdc2d0d7cb19aeea2d3fc6027cf8f59699f9b8c331b684e9860df033ea6c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:a9f684658700e5a5f9e6e7ab7a364b660e04e97ea7feb9cc4cc59f1354ec6c09
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:f78e69e1b18638ec988e6fabad23cf049477e9d9482089de29e06de19d8c8b2d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:9714ffba69114534432e435ab431914e8223c7542ea3c399cb4bbb20b11b62c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:afa7fad43d149124dd74d388e3cc1dd40911f1ef59a12b46fb01636fc9b306e2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:12d37ac2e14659faeb2fe29ae2a0fcf45cb2168e9f1c697b9d3add8fa380fe75
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:324363f51b7eae95a40e8d4209b5826d9805acb967cf095ffbe74abb34e7f0fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:7e0b05d17d5061069c80e399bcef8dba36ee7ec06a8e8f15c6adb5c09f68005e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:175d95705d6db0d669f40f27b9e2703fa9ec2229012e080e570d4003388d52c1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:92b74f7f9c0b2638f4fb53a462a42f777fc0096eb25eb85e4a510cc301849768
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:b915a99680b75ed98446caaeba4133c0769788c05d69da66b641d004a7fa6f40
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:9e2e3dc2184611bc01d586f2ab49a4652e5f1dc28d124eece7ada0c02a01899d