Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:4ec9102124a42c7aaf7662586dd8522e9e53f0c523fc7c6c8e9e9f89246854dd

Manifest digest:

sha256:020853cd4c3adaca5ddc6f91b80b0efe544c8dbe0b0c038c8421f4b6fed950dc

Size

704.10 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:9bd2b72640c218d88c3bda9bbe843aec8bc66a8e3a4d03d3ae7758ec3f9dbc5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:b7d0b811c4817b55c470cc7a881c4b754c120bafa22f3c9e347ce1ae23867d20
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:aa38280f666e4a7b5b1129020b3b129fa14d464490ec3c355bd547639f09244e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:8e1eaf8256698f21e8ea03ab64c13d5956b1aac800e8e8cd9e808325869cd21a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:b287cd97cac055147c6f644ce4eb6b3d1f672b2bc89a0a7a2233c22423410e48
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:abd446ce127ef11a3a16c92c68fa1ffd30d4de0368476233479530cd7ce134c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:4ec93fca02aafd20f9c9c95dbd4fa1d595b9f3d0e41c6204f4c154dff4b007c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:f9a4c31a74be1c87fc2292c2c07311c42b1509a32b5ca8b0b299d0cd487df930
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:cdf94808ca891a3796eecd82a9c9ff2d34dafa6a5a290ed9ee5a730a577fdeaa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:ce1a24fa563e8840d07688e3e5a1a835691978f2db1600c057c3877611cb058a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:3b388b3d2b9e2b263bd5623797e012026b54750e6c428990188991bccf8dfcfb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:f2f16e5e28c2fcf1ce82ef275ffe6ee53775fc161200a954799223b0c7e6494d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:d8343e63c28aea73736ed38f2020c8513cd282481df486f438c4b3a0dc274a94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:fe841c2f312f783696f504b16b77f43edc8ff87491e1bda6afee69b414b16ce0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:a64c15ea05321bd15459c61a1cb030b0fe3a9266efd630d479cc12ee12cb3e01