dhi.io/fluxcd-source-watcher
2-debian-dev, 2-debian13-dev, 2-dev, 2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.4-debian-dev, 2.2.4-debian13-dev, 2.2.4-dev
sha256:d340563c2b1f3778d78f8be133712e92af734841d7992ccc8c8daf71c28867af
Manifest digest:sha256:03f11e61fcfe6b21f76a4d5e3a158354246dd73739c9989c4e2e10c2d5ded1d0
Size
48.91 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-source-watcher@sha256:7715fa0aa6b8b99504518eb90179c518eb1c86895d1cf3651cca2c0ecaba001d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-source-watcher@sha256:da8cf6f5a7bfe7578c9d319f7152a194171d6c3a1b6745ae461a051c1287702c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-source-watcher@sha256:c005cb55d198487d99d4dc8e0e4d7203602fad8437bd8384f27c435e40dcfd6b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-source-watcher@sha256:7886e2c49d11add10f1bd1c7be26f048ebf3312e30e43ace678297e44351a829 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-source-watcher@sha256:2443f3836c3a7f4f054d41c73930aee862b432cb49af1d4f47686a348c7e6580 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-source-watcher@sha256:2f18043774a1fb0df52490a09ffa958b62a72585841d232cd5ee2a72860ede5f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-source-watcher@sha256:be1ed4b666ea89eea33a15125ef23cf34e6fe0a2e1dfb447bffc2716064ff133 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-source-watcher@sha256:92379ce64eed1e578dfa8345dd101f495acb44523ad07e40953e5acad8f766e1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-source-watcher@sha256:38015560e1cf8bc8fa5ede49aabb975a01f3172e91a6dda1d2d61aed40426cd0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-source-watcher@sha256:721b3ce98d38d4c8d7528af93ff4078ec4ea16bb8bfc61742cc535f3a08d6735 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-source-watcher@sha256:a3d787cf7d429d2e3b85f557adb88e756513f90059652fb83182bec9c1d92b8d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-source-watcher@sha256:f41f00a0f136191125d4f2305162836367b613aa545b0b08ed5e3717e89948b4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-source-watcher@sha256:8fa577fd59932be8507c884f9e512afdd605a1b7a2137d54acf9b7ae2aca9172 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-source-watcher@sha256:d3345125bc41fdc7f8ea2b94132600b9a68211f8cabf3aa4ec95f0ea9ee41150 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-source-watcher@sha256:7431dcbf17bfdcabf3d12fe0de73129da91913e2f9bf3b94e36f5151632be3c2 |