Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.7, 1.7-debian, 1.7-debian13, 1.7.0, 1.7.0-debian, 1.7.0-debian13, 1.7.0.1, 1.7.0.1-debian, 1.7.0.1-debian13

Index digest:

sha256:864a9707cf35ddcb5d03f283d1f001eb2dda91a29c5553b0fd9c6667fee9959f

Manifest digest:

sha256:1ae4c2dd3d641175be31a15ccbb1dd6eb45041ff54d8f02138b4fbd0204e7361

Size

604.42 MB

Last pushed

15 hours ago

Vulnerabilities

3
13
2
0
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:e7251327fd2c1965210b89d15934653be550341a8d9fa2078944b010d0799470
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:4a9bdc363bb0cb5c6d0715ef1410eb565f8f9e4235c823f5aeac1716a2e2d8ce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:2eedb4372329d49b508cb7cd05056ee06f12e41cf644366dfc72fb5c3c38a0cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:7f2983c5f760d1fd047ba10cba208788ad6ee2e5f0c4b2f4d348b75bc1139419
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:794b06cc1dcadcfaa80943ef6b0281bac870bd49a24310414706dbe83b0994d3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:e995d30868a9babf59142263e1416a1bcb0ea9d4b146c800226eb503edb34b76
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:06270ec493227396eb5325aa6b1cca9b86e6891c78c6bd9a500eadb399a6f852
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:30e2687fe2abde7adccce94be182631b4a9ccde879c8e713b092ed19a796272d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:29f4a22595a6832220d03531972644e100ee283978eed75fd25ef0225beab88a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:10bee33d97888ca46ab320101b8fcb217d774ed64f8043795403f3dcea1865a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:e27f49417a4fc38fd92e190f842ad9ec5f3e38fd49307ef9785d59e9c01bf635
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:fd17a03a9288e37b47166e41d74d7e0b37e4967bba96bc405c45a128b9fb5813
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:bd1afe87f38767b14049234528ee76d01cfcc97e28a7265182719575159e7240
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:b609d5c8e08d74fbe000e7034a73ad523e8cb852bcd5747d6a36e7fb99709f13
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:35a0533d07fc1b781b817f64166898bfe60a44ab729d64922ac637d572e4ee3e