dhi.io/go-jsonnet
0, 0-debian, 0-debian13, 0.22, 0.22-debian, 0.22-debian13, 0.22.0, 0.22.0-debian, 0.22.0-debian13
sha256:adb04ae986f4dc6763a329cc291ef0314932948f79de00aaa84583b48cf30989
Manifest digest:sha256:12dd6f0f872a5a602c86edbe2e63fec328f395c1dc298abeed6c43569b4d7a8d
Size
3.58 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/go-jsonnet:02. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/go-jsonnet:0 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/go-jsonnet@sha256:6e9b7a930f6609898d7fc98103f3dd8572765fce588e6f96cdfb210aa1282a2f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/go-jsonnet@sha256:40ecf16c67b61120d8c132ce385b38e038c8a426f07b0c1aa6fce8afc3643ccc |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/go-jsonnet@sha256:7a7de5e2070a8396e9e4ad68f8b1ad6166eb18c6a5787afe282e97b4641a5a18 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/go-jsonnet@sha256:797d0bb042aaa748dc160e74fa5c34584d0c656f3ad0ed450ea7052482497ebb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/go-jsonnet@sha256:0f83a479f1d7f1c1705b04cfcb4a041f192fea40f5d048a3e05fb3af993fc0ce |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/go-jsonnet@sha256:067177eff306b6e846593b021c7049bad0eb0f94ae61c206760a10481c2ba7e5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/go-jsonnet@sha256:227055f3c32fe797ba13aa2e8568da5b817fc05925e9274486c6c1487cf76851 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/go-jsonnet@sha256:631c9b1be595958294d4bbd7d0d71f37585a14fd37e3efcbd70ac4d374b6a6b0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/go-jsonnet@sha256:d5d79edb86b19dd642e0cc59cdabb1b9dfb1b9cd90d8e8778aff9ec5f0977be4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/go-jsonnet@sha256:4a49e964e840f4d6182cbf25236eb0ed2386306fc0320f68eab335c3b4da276c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/go-jsonnet@sha256:009097fe4dfbd5f3d9517e88d474d55a6feb94d4e747825578cf8696722f5271 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/go-jsonnet@sha256:1ed6ecfb359e9f318f16bca5b2e0ae89156a3e1ba0c581f7dc4c321a6ca5eafb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/go-jsonnet@sha256:7a315b61c9cae9e8cd5cff9f7afab326f1dbe54692d6c59aa229c9f8936a9b8f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/go-jsonnet@sha256:968313f95f27f31c59790145f114d95d267bd7a19bb400f8a93f48c8d1976abc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/go-jsonnet@sha256:987d18e634a91085dca06c063cd8e242e3db5857b3037babbd3bc3fe36001f0a |