dhi.io/datahub-gms
1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev
sha256:4ec9102124a42c7aaf7662586dd8522e9e53f0c523fc7c6c8e9e9f89246854dd
Manifest digest:sha256:020853cd4c3adaca5ddc6f91b80b0efe544c8dbe0b0c038c8421f4b6fed950dc
Size
704.10 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-gms:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-gms:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-gms@sha256:9bd2b72640c218d88c3bda9bbe843aec8bc66a8e3a4d03d3ae7758ec3f9dbc5d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-gms@sha256:b7d0b811c4817b55c470cc7a881c4b754c120bafa22f3c9e347ce1ae23867d20 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-gms@sha256:aa38280f666e4a7b5b1129020b3b129fa14d464490ec3c355bd547639f09244e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-gms@sha256:8e1eaf8256698f21e8ea03ab64c13d5956b1aac800e8e8cd9e808325869cd21a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-gms@sha256:b287cd97cac055147c6f644ce4eb6b3d1f672b2bc89a0a7a2233c22423410e48 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-gms@sha256:abd446ce127ef11a3a16c92c68fa1ffd30d4de0368476233479530cd7ce134c5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-gms@sha256:4ec93fca02aafd20f9c9c95dbd4fa1d595b9f3d0e41c6204f4c154dff4b007c2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-gms@sha256:f9a4c31a74be1c87fc2292c2c07311c42b1509a32b5ca8b0b299d0cd487df930 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-gms@sha256:cdf94808ca891a3796eecd82a9c9ff2d34dafa6a5a290ed9ee5a730a577fdeaa |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-gms@sha256:ce1a24fa563e8840d07688e3e5a1a835691978f2db1600c057c3877611cb058a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-gms@sha256:3b388b3d2b9e2b263bd5623797e012026b54750e6c428990188991bccf8dfcfb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-gms@sha256:f2f16e5e28c2fcf1ce82ef275ffe6ee53775fc161200a954799223b0c7e6494d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-gms@sha256:d8343e63c28aea73736ed38f2020c8513cd282481df486f438c4b3a0dc274a94 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-gms@sha256:fe841c2f312f783696f504b16b77f43edc8ff87491e1bda6afee69b414b16ce0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-gms@sha256:a64c15ea05321bd15459c61a1cb030b0fe3a9266efd630d479cc12ee12cb3e01 |