dhi.io/fluxcd-image-automation-controller
1-debian-dev, 1-debian13-dev, 1-dev, 1.2-debian-dev, 1.2-debian13-dev, 1.2-dev, 1.2.5-debian-dev, 1.2.5-debian13-dev, 1.2.5-dev
sha256:e3c804e03f3ce1aa53fe386ede454c4d272e054320812de1f5171b64f1b78e11
Manifest digest:sha256:5e856943ad47e35b3d2b20ac52eebbe6845f5d4b56a3e4e10b80ee23af10d2e7
Size
57.77 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-image-automation-controller:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-image-automation-controller:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-image-automation-controller@sha256:dc6fa296917b258b10827c45d5cf1c6428876409bb9601da7e8b89e5db41910e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:23772ad3cfd7f718b3867577e1fe85d1d4301f1f41ac306351f4e7f8cfff9b13 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:be2334a1a52f7123e4f83b236e46354c07bb6c0261d35b5cdaac355b8b652f58 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-image-automation-controller@sha256:64876b804f4e83b2fec3a44643333bf31d7da41af3569bddd91a83a6efd23912 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-image-automation-controller@sha256:86501fdeb39c0aa7f44bf303ad71bdb5ba4b329188f72b2a15cb7131b3d3e46a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:d6ef06876937de37edd319670b680582caabec0668413ca360cd5180c5412a14 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:555ed9dfa6a037a159066425ee336656771dc0197a47b58863db288e9f4fd435 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:12a7aadf778a7adc80a7290251717507b097c1fce2816f34585cefe8b3188069 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:b34d1a26c9e291ee3d58e02868a1cf1a21300018f28e63545604874fd43d48c0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:2cb9e589d322c55d1ad8daf89a65b67f8dc1ea9a9953bce8356b34fac0825f05 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:0b0ec2c6bcbe6c699c4dd9b0d4b6a4489147dc1f79f25d877e824e31d239552b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-image-automation-controller@sha256:c17bccfbaef1ebb5b5e166eb535aad97ebefe87eaa4963e48071dad71f29d1f1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-image-automation-controller@sha256:9158bbf5ce7f4f46b61c66dc53a01185eb7ac012f48d56cead269e4ffca02ebb |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-image-automation-controller@sha256:de6292189672e985e3652e3b353236f9368296c350a37dad74eb805c253ca1ba |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-image-automation-controller@sha256:9debe4faa35132bff725995b59e87fd658087b082b5526c8fc2775fe37349a11 |