Sign inSign up
Flyway

dhi.io/flyway

Flyway 13.10.x

CIS
linux/amd64
debian 13
Tags:

13.10, 13.10-debian, 13.10-debian13, 13.10.0, 13.10.0-debian, 13.10.0-debian13

Index digest:

sha256:113a447883319dac3747da0d6b855fea40a9f84d57b40ab24b0549191d9e0683

Manifest digest:

sha256:71859a534c5bc26435c77c4fcdf74e68f00203e1918afdfb72d6d97d4f83e770

Size

350.41 MB

Last pushed

23 hours ago

Vulnerabilities

0
8
11
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flyway:13.10

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flyway:13.10 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flyway@sha256:902475e3ea752fe3939236bcaf4889f59fea40be2462ea55589218e3af42a4ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flyway@sha256:b3402e2d3a132725e1f9979485fccb7b76eef32b92e283fe9951ef8939e9c71d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flyway@sha256:77f83158ac738f063d89f6a619a7f9e49424519dfef1593dc299c140bdbdd333
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flyway@sha256:6d6d0caa0b26c58740d9afe3ff7f3cce9be2156e15baf4a76dd7de3c60824544
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flyway@sha256:54562c3393edafadab10482aa17b0ddd6ccf2aee80b6ee7d2c3d6c18e831b862
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flyway@sha256:b457e84010792402fcb747077387cde2fb47746840f2abc3ef75026e41febea1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flyway@sha256:bfb571a8fb749330aea20016fe9fb1e38cdb2f1c42f3506c86cf176841dac3e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flyway@sha256:7b35e0663f207134d0eb6d1a122e06deee6344c6ef8aaeba3b2892f4fd7a8bbe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flyway@sha256:782c7a12d72b44394a62751be5d510b2744b92f36a8e50f0f1a4eefa074c9284
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flyway@sha256:dab72211199b2c715f286a3bd100190ce9296fa8debfa0a8f6e8283bd610c6bf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flyway@sha256:45d51d5cc8fe168e296f00944f4f98e5d0af43804f6cb2332c802d90eba46e13
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flyway@sha256:5a19c98ab5d8e3675a0b76e32741862cc5e9c48b7b6b90ddb616e1f1ce59a08f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flyway@sha256:a61dc94980f9f309d1719217152961b04538c439da90fb15c958f971f59b1194
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flyway@sha256:3db60e2fe758abe69c30312130ff68b2f81981d2926611f3a355b06dd65641d6