dhi.io/flux-cli
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.9-debian-fips-dev, 2.9-debian13-fips-dev, 2.9-fips-dev, 2.9.6-debian-fips-dev, 2.9.6-debian13-fips-dev, 2.9.6-fips-dev
sha256:5edc3176e707c547b67e27438dff8fd9cba6065ff5af5c2524c5e4860af93710
Manifest digest:sha256:53dbc15be0fcf1e565b18e89e35a15542c3d0ed9fc2e438495e07b3fec462f19
Size
65.69 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-cli:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-cli@sha256:9a8f5ffa4fa28853853af81fe4dde6168fad9f3cdc27dbcf0877ede81b9e1e4e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flux-cli@sha256:d11863b8e54b0d2f6f6b3df2b60d775801927cd7e9b85eeeff76aea8b2c7585c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/flux-cli@sha256:f500008eaad0495117e0b62cf29977e691cc33a83a2d4dfa9d08d80af8fbef63 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-cli@sha256:b04b588b56ea6bd37f224f0f2c02d2ab0fba1bdae7009f0928b1128e2b41cb59 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/flux-cli@sha256:ddcbb743909a425cdf797f854ba5ec0b4ad17a839c3969dee55a78c5fdc22280 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-cli@sha256:d60cfa2269c737fbfa340197cb19a6765373897b2b0e677f6277fe6f887ebf5b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-cli@sha256:fae6c9f5d4ca85184bd24d62fd4f8a285fa28d8a54e8bb00e4ee2c79e42c2f3d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-cli@sha256:8913d1fc98d7f35ce9d2b33da3c5c5a708dd0a0051241cdc726804bed08a9f7b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-cli@sha256:46695fe254b6f4364f048128c829bf3ba99e045fef58e5d5c895a2edf5bbbace |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-cli@sha256:4b0267f01df3d390e90dd3a0a04ec83b7b9b72ce1a4f4fd7bf90d15622d46382 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-cli@sha256:f8af4537dcf2b63ed6b803149bc5674f94a88c6b729f0f13cb46251d77c44f2f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-cli@sha256:f354a7ea28b174e99304c6af05968c9d817cc8eb8c371333f21cc150e27420ed |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-cli@sha256:074f6b425d8e124c7348f55a26a0f1e4b611640082acbec9b2cc7124811e5d0b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-cli@sha256:703b9ba166593c020819284e99ca3a2b5977d9fd62c76dd0a3ef3f588b2f0161 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-cli@sha256:4079d73a4e141f5e2f012c70df9f2da1d0e06faecdbf87c6c34962cfa2d51a97 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-cli@sha256:87dbd7197e419ca72b673fdc2b86ed1eef7ccf0ebfafbd18db4eb9d672ae8bd2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-cli@sha256:81655cbbc3068d212b1f2693fd3450df879b3adb1b952cfadae006821c7e4238 |