Sign inSign up
Flux CLI

dhi.io/flux-cli

Flux CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.9-debian-fips-dev, 2.9-debian13-fips-dev, 2.9-fips-dev, 2.9.6-debian-fips-dev, 2.9.6-debian13-fips-dev, 2.9.6-fips-dev

Index digest:

sha256:07dcc9da2181bb9d2c1af4ad98c0da19970a549e80c5b621882dfa711c51d5ca

Manifest digest:

sha256:8aa990ad06cd086106ce0a44f3950881481dde7d695785709490668ac3b8ba4e

Size

65.67 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-cli@sha256:60ef9261ac8e79e44b47c473b113365a374ddd37c634b6c35ba8201154a893fb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-cli@sha256:10d21002ce8016b263cff32c0a0c655d3a70118c22bd3dc5de51497bd504a6c2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-cli@sha256:5d8c591d191b2fb878df785465326cae1fadc4f5c9f20ad93d15ed8b924f205b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-cli@sha256:8414340366d98d90bed38f7ff43940a8fd24975a2bbe05cf34399d10efd2f7c1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-cli@sha256:59d6c21b76bd0d064402b94a4ff0ddb27df6906833e0ffcc70bfec599cd2b57a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-cli@sha256:1d86f202eb30d2b3372a210d2b0b43f3dc7462e4d862f3f0cf3c6569f5676999
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-cli@sha256:95109c06babb56657430cdb016047c320051710ec5e47e352990db2917b53ef6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-cli@sha256:d80e6fd62c17a4462268ad6882f10644e80ce48b9ac77325d9ecf849d5446dcc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-cli@sha256:35afb46304ca6511bdadf0734a5852d886c961f30308b67573e092f50457bf63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-cli@sha256:f2f9ed624a30a813d57d9af055bf5b5593a4df31638e126e4204c48753732e0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-cli@sha256:35270bfa25ca561aa4c6641cbe6d2fe925d127b24d3edb554f2b93afe50cc549
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-cli@sha256:bc145f87e76be763f90a4338611487ed72b4299956ea2dcb25d6531d9abdf3c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-cli@sha256:a1f7e81df74d10d2f2ceb4f226ee9afc2669d499999ba0a4abd6c882628a52e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-cli@sha256:8b610f3bd0c9fee943f629d47682ede4ae6122908fadac746d4cfca95cc05e3b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-cli@sha256:13e5f305cbb17b6e7360cc0eca73d1265faee32eadddc4485b12d4487982c13c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-cli@sha256:e5c07028143bc747751205202797f00480c04d5fb82a345501e19a2f9428c3b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-cli@sha256:a7e191de7b42d4f0b083c983c5b5a4bfee0cbbfc1c698d955e95023b0f28baa3