dhi.io/datahub-actions
1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev
sha256:130ff2aae6ddbc373499e6516d0cc424863b8644b1e1b6d3abc7d8a47dcd07dd
Manifest digest:sha256:ed4bdfa2bb606189f7710ca93a5f1773189be9390101aa0e5a261fb618c100d3
Size
120.18 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-actions:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-actions:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-actions@sha256:71f0f853dcc05d75ba2bc75969432d7f5f50de05c50220975441c1a8c3cc0fd7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-actions@sha256:a4a1419aaea20511910b1f7ecca98349e58c32ff6303f441b3452108e292042f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-actions@sha256:f23f2c4609fce5dd569ce0ae4993a19ab02b664615c4c596fe8d217a7b49e670 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-actions@sha256:cad202249f1482597ee63df3eabbbfd5fa633057d84538ed78d8aec60f92a07f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-actions@sha256:5d6588635e160826683669c3fb1e2f255f3b9511ff1a04010343bcc522c04da6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-actions@sha256:7590753bfb4cd4e89cce87326368b96d396fd1c4d3c3b7a22025bfb92d748c70 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-actions@sha256:534ac299d2c371842fa077b211c8fc781c9aa06f9a698a5c2771b58d4eba2213 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-actions@sha256:fc41f573c372c7fd185f8a03da59072d5f88db6af1f74b53c4815a585d888112 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-actions@sha256:772e19a361178666f412458a3c5cf504f0c6c0cf62da49a6f6f1360a495b265d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-actions@sha256:b1f43fff1d75da2931f0079694810e52a150a14ff85bd38e22f0728951a54bf7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-actions@sha256:b7fb96d28436dc8e3070031e86ae0f515d15d3970bb2fcd5d0b7b1dadd260e0a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-actions@sha256:174c0b23166a816ea7b4bb5fdfe67fdbc8f481feedf9711538ed8de07d124476 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-actions@sha256:a0a5d3d50001ce90d9d865f19fdeec8476424e7c8b7d528653fa1171d8c54098 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-actions@sha256:ddbc680c49df70d6c11a6e4a7702f97b036150f4349b49e4447388441923ca3f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-actions@sha256:2d00f3590711276efb3953af42fe2fd7bd530954c3f68bab6650e2b69b995402 |