dhi.io/fluxcd-source-watcher
2-debian-dev, 2-debian13-dev, 2-dev, 2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.4-debian-dev, 2.2.4-debian13-dev, 2.2.4-dev
sha256:980c4027e755fe13884a6965a6eafcab05ec5923fa6c95e315daac9964c3ec31
Manifest digest:sha256:70f85f7708ccc070aab719905c3e02bdd6fc7ad4fe816e2edaaf945061a86781
Size
48.90 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-source-watcher@sha256:60311449bd921f84597a421cdd7fdb4157aa182c0317b068cfab5b7a4b60e5f4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-source-watcher@sha256:18811cdff1cad0def30c09c74d134a96f04b32bc0098d1d81da8632b7cbab546 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-source-watcher@sha256:032a3d2fe50c173d8319ec6b8d58538b42a592a2b9715739ccab74695d09cead |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-source-watcher@sha256:b8c00ee605ae9c13f049500e58662bdb2812fee082eb37c0a2a6dd1831837c0e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-source-watcher@sha256:b301fb2fdadb9e8bde34ea027928964f00bb5717280b9643982a9f4b41155583 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-source-watcher@sha256:5f3669215d1586d3e86fca87ed43cf7baa18d0ea4065a105ee4d21b40d352131 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-source-watcher@sha256:c01f2cf220e3db999f5e995ba0493e190ff145bc2b3a2d6bdcd7811f0fadcc4f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-source-watcher@sha256:a1a836a0afddb9f55e78121adc20724358828bbc1f072ef8f56dfb003c242758 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-source-watcher@sha256:04d8f31c9e2e7036d539c73d807d0adbd78aad4881af62e04444a131c0797bef |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-source-watcher@sha256:b40b98b4ecf862664cc39f6b17011b8b993322f97f1e5519124990a0e652473c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-source-watcher@sha256:e5b3cace7156407eddb206832139344b3a786272d67df8ac7899d0093cdf6c6d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-source-watcher@sha256:94fa722be3c22e66ffdf6fbf0f0a7f623f2d18af80d5eb6f7523396af00fbb29 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-source-watcher@sha256:db59cf27c603beeb0d19b7c79c40a54144411d94b56eae04e55c94f1f5bf8d46 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-source-watcher@sha256:2cf092dcddbff2d9fc3e2dcc13acd18c38bd988e3593578f7c20dc262dd7cc06 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-source-watcher@sha256:f37e6a3e0105434801b9b337b98a4caeb59df834acae067b9a397821c41b8c1e |