Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.0-debian-fips-dev, 1.7.0-debian13-fips-dev, 1.7.0-fips-dev, 1.7.0.1-debian-fips-dev, 1.7.0.1-debian13-fips-dev, 1.7.0.1-fips-dev

Index digest:

sha256:c9350344921b170bba1a32241e2452332a0b5c11976d85f2d3d4329392b0ca1e

Manifest digest:

sha256:2223c77ea517b622d4bd0484e14b72e1ee0ad59cbbfe0a9d7306c6f322faf1d8

Size

713.83 MB

Last pushed

1 day ago

Vulnerabilities

2
4
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:ce85408da6d7af0bfdb2bd1cd3e71070aff575349ee88603ccd8a6be5a2f058d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:e573f2c0ac5ed2ea55d3bf62563eeceb44cf88bd8d648a1f88f3f2a81d7d9a7d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-gms@sha256:c16c0a9c3ccab7369f2d36aacdd5bc07ab2e58982db3f51fcc8c6736a2f51dcc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:7e9e76d84755754b734f9e8a610d36b0aa838c9f322165235b18fdb18cf463fa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-gms@sha256:3218737f9f9483990154e3f880310bec2df880c884ed2d5f7bf0cffae638f78d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:3be4cb1d8640155b556e879316a2a6bad857fe92e45ae2e71fa0bbafc7c49b43
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:9c95bbad76ba328264f0b076d7a4ba04eeb5f6915711572bc2d1a4f8b2d92c5f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:f3d9b97c58b3ab39c3c5e247d24ebb2db735b44829379b7410d3cbf8d609436b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:60e0e235c1a74e1c20d8e349d72d5b7b929ed56ca81dba9eb0b42f8e33aa7bef
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:6a07a03899c14575e4bff0c682518e57cb07375a654e47c411021062827018c2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:89af5aa77ba6b107b0db414ee33b670b2470f5227a79d469ad42384b7e4dcd2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:bc1c0ac5413ef223d146e4728dfd9d1e113c7596475c3fb5437bb1b78a5b7c7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:00b7d86b573ad04d4683cb8593bab160a69b76fd587c0f6ae8df7147371d38ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:b21abcca52177ecee7f94f71866f54fb9f1de4d3552fba9fec9fdace39301ead
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:09930ca20a76e126d203810a1383e84c89c3dc32bab3c5f01176a6b3ebd360d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:b0265063cad43452d7dddda6a1f85482bbc6ca2837cd4e4d42ee54f5b9737558
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:0f4ce5dfe73af35b12be689c20c4e24c6da2be6002e74d4ff533ce6bbda25095