Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.0-debian-fips, 1.7.0-debian13-fips, 1.7.0-fips, 1.7.0.1-debian-fips, 1.7.0.1-debian13-fips, 1.7.0.1-fips

Index digest:

sha256:7a6c2c9565d283f6957eadb04be5eec489e3cfaa7867792d259f34f0dbe49e55

Manifest digest:

sha256:c0c270bb1d701f7d8b651cffd671462831a30eecefba01ca93ec3e7b73dd00f9

Size

614.13 MB

Last pushed

11 hours ago

Vulnerabilities

1
5
2
0
15

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:c4080c6d983ecf68c5828f99a933ad0807bbb79a639934a592d10d91338bc7f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:1cd20778ae80c573416e7db562f63848b2206317cb46f589348c8b7501fdbe8d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-gms@sha256:085f0ce66ae1a0ad6b0b9f5f80aaea214c57f79d806678e242079e77967fbd18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:f4c92525b84b7c16e85001c1300d0b6caa99a1581bb5dc7f7067a01f868586f5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-gms@sha256:76b88358235116ad8a2cab8e4c544ee0ce46e5c34aa7f3220758eb3c4b799c93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:9f76045a92d3b5d96375623739a8734d3f77d15d3d8b5691fa632f4c80c54afb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:9fef0ed7a02b9fe4cf7043e9b6352f630783644f74fcd32c4ae946cab818fd5f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:5d683f9811cfa818cd5293a1c4b78aebca0dbe2afe8967a0d87cb98203c79776
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:87f317901f72476e6a026f971ae517f3c1f953d48cd5cc977169951a42ce11d6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:2edb9c13a5ba8b5f1e9646d0df21a5f9c752db5d1a4f65082ac2440de2424aee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:4570fec63b04734752e2a52f86bfa60dbebce30cf7f1bcabf8368cfdda0b82af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:456f3f5c6ff45160a4ee7338d3d7d4b29804494d586c90e38c547bc5614b77ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:d9c9dea9886d80f5835fc4cd0227f61d0062601512c3f912e527ffea5b0af32c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:8220addd6c23f789d55905244968a9ca154ddc40d4e2aaf72688013d0f600d27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:bee7ba97eac6f2a57b54bea0553c285a61aff9e7c8168b1ab2ab658ec5898822
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:8363b43b2e646c82bac3b2c6df3cdb1037cf96ee7e28c0f48567089e9a66c5c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:612a64dc273162fd7c662c4dc83a382d306455542394f8efedc7a18c3319130b