Sign inSign up
Flux CLI

dhi.io/flux-cli

Flux CLI 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.9-debian-fips, 2.9-debian13-fips, 2.9-fips, 2.9.6-debian-fips, 2.9.6-debian13-fips, 2.9.6-fips

Index digest:

sha256:ec56351d4147b5fe366e7095b8bec4fd370ac3c158c4c3b7540e24d1dd825b8d

Manifest digest:

sha256:0b57d4318c6734d8247869c04e3cd6992db31187a8e540fc7a967ef2e7eb0840

Size

30.06 MB

Last pushed

1 day ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-cli:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-cli:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-cli@sha256:422588e7f704057f328eea538afb47a5264ed204cee6ffa8cb896f4012a5d3de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-cli@sha256:b76ece93bd28a4d03da24a19458854d4e70e9c85a292fa3e650700f6adc91e1e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-cli@sha256:4b27fe470aa8ab8d072956db8e059333b090e4ae6083bcee2a227da2880af2cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-cli@sha256:9782ec00faed9f61233fe67be767c80c1e8ee7c986394c8812fbb683b1e52f21
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-cli@sha256:08b47a09229539c2eab25797781b9308591ca346781c2e942bf6a0eb10fdba49
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-cli@sha256:d249bfbdc1ac05d26435018531df133d882fa45aa4cf2b7b4856becf89db5c79
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-cli@sha256:87e2d012f574e2c4ab3f6a461712f896ee2821ce1691eb35972c370e49b3f079
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-cli@sha256:2d1adfef1de4b343b4107cc173474f0466c61a71e93fcb3a364aceee84fe6d5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-cli@sha256:985a9bea6156a8c19a4efae09cbb8bae8e50272e7bd516760555d5ce4b4ba011
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-cli@sha256:2780280a77f0066ccdf2d493824e945bffae84edaafdfe180c6b6ea0d7d1f98c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-cli@sha256:3a05b6e9506c753278f830449426f0d103b203292ef390ffa8eeaaad852e5bae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-cli@sha256:8bcb4974b94422ef3ec7e0fcc41a951126ced3c01d9634d0c843b898cadfe358
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-cli@sha256:3a2096533c56dd78108b5a6c2ce6f89c96a6e303b8569aad7e169cb334ee76ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-cli@sha256:fd2660a900d8efab7c454a20ad82b1f7f905bc9683ca33f24e955f824b8a69a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-cli@sha256:4e26340059a84bba7237bd729c13c68dee667e6d4bde21386e9788e09a3b7083
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-cli@sha256:32b50ba3e1fd34e19320dfb4208ae7767b87e051be0ea8761516ec23e52c7be3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-cli@sha256:83e087a4335f8e27092be857dcc3555e069373227baaa1066823f594c61fe265