dhi.io/fluxcd-source-watcher
2-debian-dev, 2-debian13-dev, 2-dev, 2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.4-debian-dev, 2.2.4-debian13-dev, 2.2.4-dev
sha256:c469a453d554d174b2d6f60d5d02e88822ad7593596bdd27fbcdc693e4e64226
Manifest digest:sha256:507610d91c3dc149bfd06d37ac108ad28d81a5d65fa91763615c2e1bd6da26bf
Size
48.91 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-source-watcher@sha256:8bf5751df954468aa8a465f08469b085b9b99a587a2a39ce2b30b8bebd9f697c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-source-watcher@sha256:dc60d918e50988d5db78bec387d9d7ee679b2a84585620f6753ab0429438bef5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-source-watcher@sha256:88d2c62c3535119fa9cef94b05e521d448f677b72b337117a1aec4e046c75d30 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-source-watcher@sha256:47d4eb430a214b314bd82c61189b39e7743f6123bbbfa0a60059cae4060ba7d3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-source-watcher@sha256:5932c03b2a55e245a1987430cbdfc875ecd630a2b752c77e0ba07a253d2f23ac |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-source-watcher@sha256:b4a74a38cb9416a6632b07c8422dd907c0d39eda0b27e87aa23cbcd6fe847177 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-source-watcher@sha256:0b9d27ab5a9ccf5e0f537f03ad09944fa635efb43178c839244ab808b499cfe2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-source-watcher@sha256:9a72699ff972b3fa3a3689e3265fa671a0a732f7895d5a0cbd9d7cc00e88b32d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-source-watcher@sha256:4d0cc5c3569427b05cd185334f975f4d2dbdef544252436aee3e22670990cc93 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-source-watcher@sha256:bffe46e1db9529e717a60fedbeeae109144f6d98c0e5a5e85ed9f6c4f3351c64 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-source-watcher@sha256:c5fd25053edf01a45d178dbf2b364b8376ddb62a19bc3d45b23b49d956315dd9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-source-watcher@sha256:eef5367c9d2647fe5fa961ca455a660f3f76602dc478c7797061395945b8516f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-source-watcher@sha256:c907f3b5fd6c509dc42369d1cee65e9428d6c8d395eaa77aa612d33f39966653 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-source-watcher@sha256:c54e810568e2d54ebed84c8e93c2b1b2d4111a3977a7719441a77d17144ffc2d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-source-watcher@sha256:f89eacfd2a1193010010fb570415b95c766235019c4968e20550abd23da04d46 |