Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.0-debian-fips, 1.7.0-debian13-fips, 1.7.0-fips, 1.7.0.1-debian-fips, 1.7.0.1-debian13-fips, 1.7.0.1-fips

Index digest:

sha256:7d995e82a8f12731f5172739758e8125a79b76420c108e589da52acce404e40e

Manifest digest:

sha256:cfccc9db7242e06b1e04f3104d4daa2ff3c0e6a3e9488f71a577327b5a9fa0d3

Size

614.15 MB

Last pushed

12 hours ago

Vulnerabilities

4
12
0
0
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:9c930070e335a7529fdc212aa10c82fe42d5b57b5a957f595ff5dbe4e6e8cf3f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:5991e0922b150b97f1cdba2df9f481e61fb6ec4e7571ff1d10f1a32c6bddfc83
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-gms@sha256:2c10db2269f496d9c8c734a64c1e1f7407ddcafe1dc18f601022d3913596cc3b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:fd2b228acb2ae7a2ace96901447e53b805c461408018655a1e3a257e642c1011
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-gms@sha256:bc8a690f1a2c9a0ab4a8b2efba9405b7223ed7bb99733d74c424d44455de0688
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:5cf67795afbdce4bed4560a332d721a3eb61b7d0e8c93a708cfbde0fb8b45b20
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:f8afb969db0cd5d6c7c1c4af8c929028e1727daee82880c137dbf8b3513d2ff1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:61e2df755c70da51431045c4cb3d1f5df8c3b024cc101a343469a55813bbf38b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:f54c71b4edc58b3b2b7b0087f9aff8717e53912267b23115ac89444a770a63ea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:5b2c0f193710af932f77863966255ae019afdd2c15b0ed948453f89cac727569
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:08c300cd34f7de812326df1289285c39ea2ba850bce8cc595e8f1de3bf69dfc1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:5e6051243fd4421cda99583dcaec87b1f2bba7ae295cbbd0a1309fe95f5201cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:7e1e03d64a301e5af6865760ba2a59be20f743fa7e3ea058fd0048e25ade0869
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:cbcee14ac598ee2be2167babd6e51e900c98c2ed295b3303476f6d950ddbe839
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:edc84197206a5bed46df4e68c8f8d1be1839a1d24a13330eb539038eb39e9343
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:060949f11d82328eeedc4ddee0c373967fe9debcceb951240a7f8c0661ebd7dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:70ce6d271862cd71f25ea0d6390c8df8344b277c99000d9e715b5601fa9feb0c