Sign inSign up
Descheduler

dhi.io/descheduler

Descheduler 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.36-debian-dev, 0.36-debian13-dev, 0.36-dev, 0.36.0-debian-dev, 0.36.0-debian13-dev, 0.36.0-dev

Index digest:

sha256:dc3570c8e30eaae9969926d6ac44c4acec2bc17ec0b280f9a9932fb8a27bf9d6

Manifest digest:

sha256:0d422b02aac9c7e6bcb72f7dda6087a0081b1f773b3bef119eeb7b65806cebce

Size

61.60 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/descheduler:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/descheduler:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/descheduler@sha256:23b4cb4714746d42adbeca795130bd490137afe31d44d411589c3051bfea1fcf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/descheduler@sha256:c95940eba35a04eafbb6b930eb111696157fd901fa016573fe98d45e92dfb379
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/descheduler@sha256:96f948cc3f2e841b9bc87d405185ee2b01e4e9365b441611d8366be6b56c2e62
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/descheduler@sha256:e617a4f7a5100f82a555bc38141c124d3951153ba0339e15d153fbc554519798
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/descheduler@sha256:a7519e1ed3dc854894003445068ca4aee6e13c1f3027f09140434418ed045bbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/descheduler@sha256:b027fa1dd81ca2c2a606e44035116a86fdece03ee2bb4660021d7c3b56b4251f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/descheduler@sha256:b8af0813035f68b00d079a07ec1a15dfc1c58089fe751148f16844db5140e18f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/descheduler@sha256:8a2b50d02ac2d70084e0da0836a332db32fac9ea9aec42e83204de1ea6c7a7af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/descheduler@sha256:fa36c48d37888c735aabe0a44c40928fa32954f79804daf008f4804a2d835734
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/descheduler@sha256:afb181140aabd3076927c1316e651ef2f955412dad3a519b6941830b8ab7f092
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/descheduler@sha256:edb533dcea59726d966d7d64c0448b8152642e88dd47d659344cbc202155fd41
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/descheduler@sha256:d52045694a3cfdb1922da13113877e91d76bd034299e4ba6b2bc56b5a1e624da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/descheduler@sha256:9e982c03c46cadfa9e10fccd59155c332c5c98fd53a0bed8acbe1bf6c1fd06fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/descheduler@sha256:5984b95dea2726cb5d00c6fb7f3e557019124089673df2bf49d9b9ec8142bb46
SPDX SBOMhttps://spdx.dev/Documentdhi.io/descheduler@sha256:ea39570fcecd402c37e95bae9c82ba7028384cb202bf80c428444f94c074ce45