Sign inSign up
DataHub Upgrade

dhi.io/datahub-upgrade

DataHub Upgrade 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.0-debian-fips, 1.7.0-debian13-fips, 1.7.0-fips, 1.7.0.1-debian-fips, 1.7.0.1-debian13-fips, 1.7.0.1-fips

Index digest:

sha256:55487e9443ef4bc33d51e286c4d4c94c43a0f7e91889d752b6d74c5f0d28135b

Manifest digest:

sha256:e1e90011b63b6bb33bdd6d8af0d514c34e40563e1c5ea09cdbef2a08907e781b

Size

670.57 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-upgrade:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-upgrade:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-upgrade@sha256:4610a23eef5d4379d37d65f1cb89ae12465d84ba60a8fb9a3954576c590d0041
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-upgrade@sha256:120c34f57cf23a81da4038f95363796d14d61ede7c352365cd4a5567af0de7dc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-upgrade@sha256:7d5954712c572d26c9226fa4be4933acfc9a394d1f90b254f91ecfc2f1f34e2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-upgrade@sha256:cd98581fb9b00582cc73c298598cd65c3e9d53618b38df47c806a0d3c88b9854
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-upgrade@sha256:3e30ea1ce09504f6bb4f10545f1d31da568be4004f061366731a82bb815301db
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-upgrade@sha256:c75cacadafa2851c31b41d2d626d4b54815d1646df85a1b4028d3d34b763b2ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-upgrade@sha256:c59ac3626c317b29d3a56db52737198a6ccaf2484c37fd9464f09433dfbaf27c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-upgrade@sha256:7f586562adc1eac45abcc92a13bc2c7abd09088f10375a2fa7c6d9ac810bc5db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-upgrade@sha256:787ea213664c5aeb6706757a9094e53feee64430decaadfa7ead4f028125c9cd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-upgrade@sha256:63ab2d26d337a6187a38768bfa86710c1279dd6565069be82fd3cf6a7f403af5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-upgrade@sha256:9586cbbdac9b694f8e19d4489b53a0d6d4e281e2f90e0b804e5ac191b77d626b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-upgrade@sha256:43e8527f22eef00a223c77b9e8a76de352f6ebf800a86fb8ce30d0e03270a29b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-upgrade@sha256:2f96ad76e3eeaecb4837880c77767f9f838b47323bee3a9e8e1ac012b5762284
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-upgrade@sha256:426dc02a138ecd3e4da1159e989e54c12195156588e2670e010c452e1a47166f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-upgrade@sha256:dfcc93a398e86beb26af65fba30c4b70bac08e16241fa05190d721e51f09f102
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-upgrade@sha256:54e5bda8adc107bfce929492cc84289eaf5ee708f60dd7b5c99d667590ad241f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-upgrade@sha256:1f3ec5a751c20624dca467e5b6cd9bf2deb3f4e1e9c196cf3befed9e2c3c64bd