Sign inSign up
Dapr Placement Service

dhi.io/dapr-placement

Dapr Placement 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:28dd25591b280a51d4ca3884aebf461df5c2f631af4a174f076e05e5403b6eba

Manifest digest:

sha256:2ad692dd44cc78d2a3b60dd58697bb62264661bf14b3cb97db7f81772de05a10

Size

48.65 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-placement:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-placement:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-placement@sha256:b02a48b281ee58adb68a9c141cb5574ca4755a895057a84795af303e0b298e65
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-placement@sha256:4967a5436e5c044e11fbef4cf7366e1621cde9c783d9f6e5069ff3548358e27f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-placement@sha256:ad89605b2cc56d8f953cebd58223250c17890066c3db1d2f1b66152ace7cfffa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-placement@sha256:d6f97b3732452ba2ba1d2b23dfefe3c770e7562d168595fe91af47dc11f1b1b5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-placement@sha256:9734c16a90e9be3de4b104da011bd3b3f978cbe536e7eca4b88c72db7596643c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-placement@sha256:5480854059f4795aa3b05c280faa19f41430db45e57b0a6abfb6f3ca08a4ddfb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-placement@sha256:0b7e0989316d5c8652e9a26b6089d6ed5cb1da99714d75587bbb9e4eec74ae10
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-placement@sha256:38b7bf4e43b54908ef9034228e9b3cde6778d26451d5e5f15d0f4b64d55fa15d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-placement@sha256:b8caf2c9c8b4b59a17a0ffe094d5ed30874aa8d0cb580b7a6bf4705c46afa21d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-placement@sha256:19670500a5123f64a06d1806ef873def4488a27bc4c8825c41bf0480567d19af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-placement@sha256:6111ff0891da141a5674763f6e155821bb646b25a96094b6a346a21c1e8ca49a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-placement@sha256:66bf5f600771dab42e3780f5549b1f19ebe0a5d5fe6711e6f300d281cde4118c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-placement@sha256:0a53867f2a2b546744484ff78d238c6fcef8765c1138d04ffc311458abfc56f4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-placement@sha256:8706ea11b03d746eca3df7b5f8a4b72e040775666ddf4c50c62fa93827a4918c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-placement@sha256:ea1d2909e8fed1459dc98006b9299756b8364c6abc37e6f1a78deeb436d298c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-placement@sha256:84352d91bb275098b25920e5ab8f62dabaa17f20fe88de672ae7f5c58c178f12
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-placement@sha256:013a70de67460b3cbf39b96f7be1bc7c8113f2bc56364361a48ba7e0ff4dd73b