Sign inSign up
Flux CLI

dhi.io/flux-cli

Flux CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.9-debian-fips-dev, 2.9-debian13-fips-dev, 2.9-fips-dev, 2.9.5-debian-fips-dev, 2.9.5-debian13-fips-dev, 2.9.5-fips-dev

Index digest:

sha256:adb5f661e1c16315d96ad39ade7418b8c3e687f954f023191ca76ce834e72d84

Manifest digest:

sha256:4e22bf37c603ad8d99139b9db83753d56a5c2449c3a2768e7168c621d925938f

Size

65.70 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-cli@sha256:3e8c746758d61ae86301fddd22faa191629f171fc4dfe3a7c7f38de3e87b6a4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-cli@sha256:5b0200378aba7fc72ad08d2520d1b5684d705169e88c8863d2c70c53f0735602
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-cli@sha256:b51f13262eca0a1a2fa17b269ca7b1072518fb73e2091ef0f701b9246e0f1a22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-cli@sha256:e879f030663ba0b50fee44da83dec14b72d35c5e8f1a2d0cd60f3804e7318ee0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-cli@sha256:2989216266f88995fbe7ed4fc90ae3424df66db9eb93c3092a88d7760462dda0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-cli@sha256:922a2f63517476efd8a4220d305fb50ad5414531a186a93e4d0a95136cd69722
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-cli@sha256:300bb2a450496f4dff944e343ad87b19e985283c21c625576be3be62b0c7d990
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-cli@sha256:8218470216f4732bf2f9891e24fe76c0a3b12f8019480e4a482e0932bafc1e22
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-cli@sha256:3fd421f08ea0799ed4b866af6d92f531b9cfc85cb8ecf61a816337c89f656b93
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-cli@sha256:8a69b84b39f1c0d462757f63a1a05053e490b658c90467b93f6d8b833eb88de2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-cli@sha256:d318e69487bde98c192b3d95029c40f0d0d757d7b9681995ca3452fae2c3cc58
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-cli@sha256:941dc5a39b4b4ff73bf3d4db73f4ad5075f42cc649b196953d4e460de0e94b2e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-cli@sha256:7cb8ccf30b8ceb56fc39fc8d52e1db2a3405eb526372504e52163eb4e8bdb583
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-cli@sha256:c0e00bed3945dd4b41fc7a1821f15be2eea5c759117bbcc0cf4027b7a593e0bd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-cli@sha256:69ebb681a7e4fab69bb108410757dd1cecbbfce137532b50b87dbe7a2a32ddfc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-cli@sha256:7358d0555e3e3f4ebbe00217b64e08b631abcb1cfc10c1a76b401376cbe312d2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-cli@sha256:6991ee78b664b4c287f6077cba4c80cfedf337dba3e58f7376ea9046d6bc3b2e