Sign inSign up
Dapr Sentry

dhi.io/dapr-sentry

Dapr Sentry 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:a0331e0d507365452e267fb05cf317e17ba4b2d187f625a6b0bb21a6b9d80d7d

Manifest digest:

sha256:5dfe4900f2d51d7a06d9b9a36372579a43be85b33e1f6b6047b5c5825befa28d

Size

51.85 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-sentry:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-sentry:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-sentry@sha256:e9fa28f0ada0d4df710364923b4024eece22a5214ea55840b7e462d7f0d4cf6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-sentry@sha256:7c58442382f85984bef1225958b6818a882e85f029cd0ecb186f40cc26dc4c28
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-sentry@sha256:a155888829ad0c40d95aedb23dbf61bebc21f03f1ddf956118565a6bb4e649d7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-sentry@sha256:5fc9a8d1cf8c48e3710f3ce04441447355d685d146e67339589855e1f0e42521
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-sentry@sha256:3af8c60b71ccc331170b3470ae97568df84390045a2e6a3e1db5cd4f147b1ca0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-sentry@sha256:927a0a879ce01968f3347dc2371d9918d7ac1e431fa5ff612dd0abb9867d6478
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-sentry@sha256:3931a2d9641e08ec3c5f39f0a36f5659d537e85ee6987dad17f41a271da8430e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-sentry@sha256:31b80a894f1fc11ee497a59fe22f3002ad9762e4a7a467079b2d81b8b6d540ef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-sentry@sha256:c6d1aee659d98ddcf9d7e4a355148bad813ace239eacd1bdd3139359532f184d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-sentry@sha256:0a4453fe72f888ed05c1b7b9c4829b5155a5caa6918e92f8bbc5a17e5a7eeedd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-sentry@sha256:e447e19be494e6fceab77c7b673ed304b57685071a86780b51401dd12b078425
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-sentry@sha256:9b3df2f3b0fb2c0e94674f69ebf44a8932d20cf2de029c13f5496c51601c0fca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-sentry@sha256:54012d8aa8d40bd596c2720df49b05c5a977af80ae27109d2e744f4cfc8e7e5a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-sentry@sha256:0cccf5598a092480db56c6b9c4c045241afc590e6ea837320143bc6f812bd681
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-sentry@sha256:899d46e289d846838f3d5ba202b911ffe9d09f4de9e506875e23f1a0c961716b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-sentry@sha256:3cf53fcc0924d3f3520b4c547027a3065b8bb17eed5acfd31e79f062e656feb9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-sentry@sha256:29fecf5deca0d397cc03ab0d78f19ab2114ef156305b40fdd7ab3566fe01dc2b