Sign inSign up
Source Watcher

dhi.io/fluxcd-source-watcher

fluxcd source watcher 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.4-debian-dev, 2.2.4-debian13-dev, 2.2.4-dev

Index digest:

sha256:d340563c2b1f3778d78f8be133712e92af734841d7992ccc8c8daf71c28867af

Manifest digest:

sha256:03f11e61fcfe6b21f76a4d5e3a158354246dd73739c9989c4e2e10c2d5ded1d0

Size

48.91 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-watcher@sha256:7715fa0aa6b8b99504518eb90179c518eb1c86895d1cf3651cca2c0ecaba001d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-watcher@sha256:da8cf6f5a7bfe7578c9d319f7152a194171d6c3a1b6745ae461a051c1287702c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-watcher@sha256:c005cb55d198487d99d4dc8e0e4d7203602fad8437bd8384f27c435e40dcfd6b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-watcher@sha256:7886e2c49d11add10f1bd1c7be26f048ebf3312e30e43ace678297e44351a829
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-watcher@sha256:2443f3836c3a7f4f054d41c73930aee862b432cb49af1d4f47686a348c7e6580
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-watcher@sha256:2f18043774a1fb0df52490a09ffa958b62a72585841d232cd5ee2a72860ede5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-watcher@sha256:be1ed4b666ea89eea33a15125ef23cf34e6fe0a2e1dfb447bffc2716064ff133
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-watcher@sha256:92379ce64eed1e578dfa8345dd101f495acb44523ad07e40953e5acad8f766e1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-watcher@sha256:38015560e1cf8bc8fa5ede49aabb975a01f3172e91a6dda1d2d61aed40426cd0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-watcher@sha256:721b3ce98d38d4c8d7528af93ff4078ec4ea16bb8bfc61742cc535f3a08d6735
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-watcher@sha256:a3d787cf7d429d2e3b85f557adb88e756513f90059652fb83182bec9c1d92b8d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-watcher@sha256:f41f00a0f136191125d4f2305162836367b613aa545b0b08ed5e3717e89948b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-watcher@sha256:8fa577fd59932be8507c884f9e512afdd605a1b7a2137d54acf9b7ae2aca9172
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-watcher@sha256:d3345125bc41fdc7f8ea2b94132600b9a68211f8cabf3aa4ec95f0ea9ee41150
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-watcher@sha256:7431dcbf17bfdcabf3d12fe0de73129da91913e2f9bf3b94e36f5151632be3c2