Sign inSign up
DataHub Upgrade

dhi.io/datahub-upgrade

DataHub Upgrade 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:785b19354246cc1f8ee479137cffe66640e078882c9bcaa536996381c4527bb2

Manifest digest:

sha256:53939cc5a4eaef7988df903a50d0c3698949b95805c551cfb2e968e6f7ec5b0b

Size

794.75 MB

Last pushed

6 hours ago

Vulnerabilities

1
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-upgrade:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-upgrade:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-upgrade@sha256:b57ffef35975f29c275d5bba06c807ca1a353e6d40ae7cb018046f63fe047f40
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-upgrade@sha256:a9a388653bb2a42e966ee4b06228d66a429a81ca2b6e06ec7f39026f7be9d8b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-upgrade@sha256:db1be0675853b8a8dbd150d12e47bdcb37586dad92a24e0ba15951fa9dd7b868
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-upgrade@sha256:4b58343eaf29cb424fbc2714e82b04da3528e199fb02bee6ab47068d4e5c4c84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-upgrade@sha256:505356943edc36bc4dd4c25d8b1cb979e411f924d738a29d532bab9160b3b1a8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-upgrade@sha256:0ef24e23c984962d2d020a63c268db1a260ad6a75058d50537bfa2a4079f8719
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-upgrade@sha256:08e656ca5bb346bfd4687c1f3efcbea2295194d8de038ad0f05b671c8ba8a1d7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-upgrade@sha256:07e2f987fe29871c6735b6d5e263668d4195d56c4fe75af59ced23044e46a81e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-upgrade@sha256:bf2dd51ca607d1448befc082bba27836918b701c15bc133c788ec4bac3970ccf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-upgrade@sha256:8ac1b30b0fde313dbe6410b6f0b0640dd04017046d3fdce2855759c4e36c3af7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-upgrade@sha256:a6fe1bbab4ccc49638d92299b299078e38201636dae597e196c1f7cc302d04cd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-upgrade@sha256:28742399bf97ed00511e093e16cfa4b208acdb80d4b25bc7cf49b9679439aadb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-upgrade@sha256:3f7c32695e5eb37252c764ee1274c0452cadcfc5cddb915df4f35f39c04c5ec0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-upgrade@sha256:d8e58c9850fed6e63a1709dcd99667ed490bdb757d54445fff795a592284a6ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-upgrade@sha256:99e8fbaba39e8222e11fc42dabb9b1bc2daabfc557a5ec3792b958414d1d8add