Sign inSign up
Flyway

dhi.io/flyway

Flyway 13.9.x

CIS
linux/amd64
debian 13
Tags:

13.9, 13.9-debian, 13.9-debian13, 13.9.0, 13.9.0-debian, 13.9.0-debian13

Index digest:

sha256:6ce35bc67da194f641c055c9bc4abf15cf611c5c667eae53fd3b0c94d825b6cd

Manifest digest:

sha256:0b2a3e774315856cdca3bceb0db014f274611503e65952a7c30bce12a43ab4d9

Size

350.39 MB

Last pushed

3 days ago

Vulnerabilities

0
8
8
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flyway:13.9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flyway:13.9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flyway@sha256:be4092f988176c7e35e2af757a29c406674de5e331b084ca864262fcbc1ed872
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flyway@sha256:841e0f6fde962c9d2d3773b70b1c4cdd0e27d8b83d8bd731a034514468c7c656
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flyway@sha256:590506eb4758f8d84d4ffb0422bec9621c92fbf8cf43458e89cfba5f59c256ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flyway@sha256:cbd3830a12a0a00851945c7f606a5dc9391a026c4cafc4ba0a9789d148d37a5e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flyway@sha256:a9fbe645750be4a920bdadcf5e8bea421b2f5e6136450206f4231ea7bf5564e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flyway@sha256:c14f533577eca3aed589644ec9be44aaa04242f54932d57018353a81b3f7546e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flyway@sha256:13d07d472b5100093963223b03165d53d06a6b9a60a9e4b4776139e98a6875eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flyway@sha256:114c82c48184f8d319107e75bc1e1df3a23a4c201d14e2122374af6e900c9e8e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flyway@sha256:f2a0352a0ae9d9bbdcf1bb1e362f31e61e76dcc0f9a3ec871e4341a94fdf3994
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flyway@sha256:c9a4f8f4dbc41f067da96ec63dcdad7400f485dd80f89667bf992507cc8e03f0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flyway@sha256:0fb9639d43d42eb0a0d112519a31da34db23fab7d9c972a9c651f2a0510797e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flyway@sha256:a427d4d48845a5c6932d3b7b0f34f1920727f61740d2ce3466d09c987a83b324
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flyway@sha256:d38a94da0a3ace8181aa60c02cd942248fbbe9ec894a9e5c92173f9e4d1c11a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flyway@sha256:84f6ed253473b52b693a4b3e74aa4e485ab7ab52ca2036c34b09a4b46de9c0a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flyway@sha256:88d7ca7280a8f38c3545b1ffd1394e4ad8f091adae8419fc172153875f5d198d