Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:ef291cd9d12f1bdefb5cd8ee54d1a1c5ac18028fb312a730b745bd7b46ac70ec

Manifest digest:

sha256:7b2662b8172c59fabc989501c80c36bd55b132fb7031e0226116abc3941e12e6

Size

703.97 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:c26b81c5bf1d8dc4e4ec33dee1de33a5148a93944a09c59949ea79ec5e810d97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:d75ca1ccc7e3e4ff2901a95e0eef8d85e79e5637fee34c9b87d3ff0c2da91cc7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:c3e057bf819c54cb421099506cf06b8a99fb8ed9bf05062f070bc20157b7597c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:e34632353c1ff4f591718df89613d2ec57c3fb78748a4c372480623e1951dffc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:c88f1de4848549d14d9bc1a1a2c83a15f8944bbfe90b6d45d4c18b73a23960f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:774bba0a8a05be7a3eb3228f7746e3bebe4d21692c37359c5e954be05bd3edb1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:0dd3ef835b66ae86fc2804d9c85a8e2caed7181fdb4551d68fbe714deb7cb8ce
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:d6ebf11f4ad6269ca38977700c284d056f35ca773d8a1cb8b9314d1179aa705f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:6cfcdb268cc185cf75f9a7e8b752c89e011c310561445de14f3d5582fb445c0d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:58cd82fb3909e8c291b5f227ed5af8d5ce4c13f3b07e3a436d88ef9e8d2dfad9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:e5174c4b23a12fdfd74afc9d7bdea503492b951fe896d7837a430e94bb1dadc0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:017f93f194cfdcc938dae7dd9a7d1c82e9e0292922179e8b20cb8cd0510149ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:bdf16030c968a3e172c39e7c0305d0e6a3f119e8956205bafdd42dd412f1b53c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:e0b0124b39378de7a8a37f3195e819f883fbad5c47b34e513d90ff106ec6297e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:a5492220e9b63341b5c6e4d1c349b37c020ce3118cb857de7538b21880300b36