Sign inSign up
DataHub Actions

dhi.io/datahub-actions

DataHub Actions 1.7.x (locked, dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked-dev, 1-debian13-locked-dev, 1-locked-dev, 1.7-debian-locked-dev, 1.7-debian13-locked-dev, 1.7-locked-dev, 1.7.0-debian-locked-dev, 1.7.0-debian13-locked-dev, 1.7.0-locked-dev, 1.7.0.1-debian-locked-dev, 1.7.0.1-debian13-locked-dev, 1.7.0.1-locked-dev

Index digest:

sha256:02da9946b07d00be37432b15be98b6246eaa1ade891a1496931172d9e5ba14ba

Manifest digest:

sha256:09b09d19b9f5ad34618fbb16384d7c2839ca9ecf9502ea4ea8b6a4863844d8d8

Size

88.07 MB

Last pushed

9 hours ago

Vulnerabilities

0
2
6
11
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-actions:1-debian-locked-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-actions:1-debian-locked-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-actions@sha256:d3c2c069f941fe0d4c4555049793eb06b38b651c07d95d7bd7f7fce077586ffc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-actions@sha256:09c96078e2e4742c6c19f373aedb08504bddd1db8a9548785d25780d39f0384f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-actions@sha256:73813f6342f832fcddccb5764323ae613249320e2b016dfd3e8520393d65a9fa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-actions@sha256:b96f8396c922e7bd8a0c75c651dc2d024a9e6ea86636dd047178bb3065523b90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-actions@sha256:7bae40331cb531b92b08989c8693c7489e50e309c5d680d9c9968a1a3222ac09
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-actions@sha256:b7800bfa6947eaf6ab94181577df82186deaad4f996fef3a5580148a8945dbd9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-actions@sha256:3486c9a0bdfbcd98ccd87f1911dc8edb286ad96a86a7a6f253cc0ba311c1ae63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-actions@sha256:26eb86fb252b5b4ac81f09e7bd0da497f6fcddacb6731ec08a1327d2b430bc97
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-actions@sha256:4b5d81e406b07764bc47399a19e33efe77938937929a23d0edc1e56cffd8658c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-actions@sha256:1b088fabfe956d789458119ed9c9214e604560495d7fc37cddf9765f46909677
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-actions@sha256:6dcb6064190197d6271d99e994c489abf4ced56b27538dc8b162a1f51cd97b4e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-actions@sha256:9ae8680c19f29a47c9f7e53670294e9269bd47a8a17c930e63c3ac4765bd44f1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-actions@sha256:732107917d5c9249b857dc85c7d66f7f781f442bd935f776459581443772186e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-actions@sha256:2ebe750dd0b95cf6191a002d1862d436959d883f9610ca0ee6e5ba596978b634
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-actions@sha256:aed6c5bdca87f4cef33991117400b37ba8b6b6f056706c5efd471fd2bbdd64b1