Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.0-debian-fips-dev, 1.7.0-debian13-fips-dev, 1.7.0-fips-dev, 1.7.0.1-debian-fips-dev, 1.7.0.1-debian13-fips-dev, 1.7.0.1-fips-dev

Index digest:

sha256:5c0f35d0af2398cd44ee474614b00476b15882a9e100cb6ff9251a21fa81f5c1

Manifest digest:

sha256:a53e2f946eaff4c37baf5e2f47de33688b372adba26f99aee9190a13fefa0f15

Size

713.83 MB

Last pushed

12 hours ago

Vulnerabilities

0
4
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:81b3c307bea8097782b8e70b61fc78aa7cf6148de539a2e26d8f6c7e06e73b0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:e60aa9d752b5d33ef30c9d70a0d4e633560405b2e1809514fc933fcbd8a0a2e4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-gms@sha256:346945f15a973d2e49af6ae40ef0255353bca850e3babfd471ba58fe218a5d09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:603286912dcb2c13601d6095c27f9ac1b994e5bb42ce7f7d9b668ffc6d1b0c35
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-gms@sha256:25a7d9aa614335b204a95120d1aa9e35ae29736ad0d3705d3316a94539bfa096
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:73a3660a0745c89cae6081c003d991ea0427e5c1d4f810a4a32465672835c67e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:0efc420d4acd670c301955b4383884d097bedd247663eb8748dfce69be265445
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:31339130e3d7a1eaecc506b507b42c91bdcad73a3a670ad5dc6985bb38043bcb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:452cbce02c5080599ce41243370c792fc5ac5c518bd64d1979c0e3734b39afaf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:d3f6c245fabfb225cd68b9318b7135a1b74d1025b524bd014622d40f88ece736
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:ea8007e2cf7b2ecd2c82782705b9cbb7dd345051a75c05f9a226a8c168fcb0a3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:d9285f07e07ea5d1d659c1863e983354c5369c6218ebfb1849110a358149bf21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:07711f21906180e646d92f9ecf0cc9283bd207e33e0c9ef64752201cfea1c52e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:5fc64d326e686788963fb6ca9d9d46d565a64a9a728a051f03a336684c04a630
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:5ca255f02fe8f8cfbd90c03cc377a47a8c3356e6c10770be1017321f6d24466a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:669df611638b874a155961c80d262b67ae57378b4a7a5b93400ef01385227121
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:17e326fa05a9a302e9881f8ea103b1586099bf972ce01ae7cbf1a0959cc6ae59