Sign inSign up
Flux CLI

dhi.io/flux-cli

Flux CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.9-debian-fips-dev, 2.9-debian13-fips-dev, 2.9-fips-dev, 2.9.6-debian-fips-dev, 2.9.6-debian13-fips-dev, 2.9.6-fips-dev

Index digest:

sha256:8f9e43eab4db99b57bf0bde12d2079eb8c7f26647fce4d633007a1fb6df395dc

Manifest digest:

sha256:ac1b5485092f728857eff0e1d12ff7acab60ee60e8c30619d30a5339f0a4e3ec

Size

65.67 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-cli@sha256:125b401a5fded19fe03c9564702e026324674ffb10421d073299aabb97368dd3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-cli@sha256:fdeadb9a99673b75c96ae378cbe7106590402fa03d276b6706a59e1a7d49d05b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-cli@sha256:bc2983d13ff28bdc46768d532e5f2e725b6022970adc3bcc48c7e9ab329b15a9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-cli@sha256:1b4d2a43067fab6ee115606e2382a023b5495cf869b3f7318641e4cbb439373e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-cli@sha256:fe29df31e3793c4f9070816b15c72d2f967c3ba4ac623ffce53aea76a7c53c45
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-cli@sha256:57b8f89b51bbb3422c4f044087b987e3ac2b81a533602a152cefcaa9d9d0a7a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-cli@sha256:9fcdddbf3ec6cf4d4670da6186addf24f028f2063e9c008c74e34cdbba4d3065
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-cli@sha256:faec1835c27193dc46f98765f0bbc32189b85bda84a7fcc160d6479343465c04
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-cli@sha256:118c1c9803b9647e05e1dc672dd469ac9c06833362fd8834dbfe073daa1b9746
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-cli@sha256:a43c7f28620cdafec291da83fb53e1f8fe4134287c559c742ef0e9605ee92386
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-cli@sha256:9aa1c029cd21b14ae2d2afdadaf294826fd57ca9bb56300d8d927b064d67da8e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-cli@sha256:f913f5af826d6d04d6e2679cbeac1ce54be636b4af60eba07540e93aa1083044
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-cli@sha256:48e24833c4aec6874b587c55f48f79fa9a1a2df62c26d35be83fba6664884101
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-cli@sha256:96495b84692e59a2a3eb9c90e06bee7aa88ea5109f2f6554c33031ac41ac80de
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-cli@sha256:d3be4690874a0bea65be202d3154be6e1244a584e2697118623d64438eb0f501
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-cli@sha256:1228ed8d501302792f3542c94d60cf295971c78735fd7b0651f6b8ed711e7653
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-cli@sha256:35f24389438838ec03081bf5b131ace2f5e0a9d18ea4bb0a0739ca9b3657d777