Sign inSign up
Helm

dhi.io/helm

Helm 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.22-debian-dev, 3.22-debian13-dev, 3.22-dev, 3.22.0-debian-dev, 3.22.0-debian13-dev, 3.22.0-dev

Index digest:

sha256:6916c931112df0d9475c9f45e04efddbc9ea75d221c22b1431e5c4a257c6a95c

Manifest digest:

sha256:ad7871807b1b7cc6d81951d777abb247959bf50ab60ec82b259bef360b2015d9

Size

59.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:2327061f9b0e03a5f74d7d72075caed727df066c7afc86af7bc35ae280074c82
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:55f10c7ad92899074670c7e1548a344b998e1010890f72bb7ff00adf782f9ae5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:222f1cb4f8ad8d485b2e44b9d7bdcd5ea3b89c075b6fb753bd7cda65d5b3821c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:d2e09668eed0dff69c57de91cc2435379dc2da1f70e2a11bb856cf635a283157
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:5cde7df76320a24c2d3e4507e4b078a6eba6d2dcb84e01bbddda6a3d5f940046
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:47a75f183afa944355c1f0154c614b5cca58ec1286ffc4e06d48cda6c3276369
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:5b62956938719d7a266ff2c5b325365108bc0309817a98d8b5eb9a316f9f2eee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:81d5c805f9df138610b00db455edb0c0e01303f8875c70929f39688722251a05
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:c95963b75acafbeb9e1a18fbd79306d7bf0bc4e7f762099d921165f071962c3a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:2cb87468a36475807bf565ee69835459a85501d62eccb3076319be69396da120
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:448a41cecd301c96f0fd8b9b3a9e6661da71b8db36fc66793906f4ce5a0b2859
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:9791db509f2aa706f16c850dc94c0119dd573c98d549255d453c5a8e90dd132f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:ad4681294659950299b0524aedf5346403f88f74a066d4d4448824879284092d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:186ba333ef01bcc25c778ae1c8a15a69bbddc7ffc6cc06555a593a77e2d62e90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:7158d02aaf71ca2b4ebce8ab106bb519aa15d9a1ee8b9816df9f6290796bbb92