Sign inSign up
Helm

dhi.io/helm

Helm 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.22-debian-fips-dev, 3.22-debian13-fips-dev, 3.22-fips-dev, 3.22.0-debian-fips-dev, 3.22.0-debian13-fips-dev, 3.22.0-fips-dev

Index digest:

sha256:2eb844cb66eed05b3dd5ccc49e0655553edcbb012cd00699fdbce163590160ba

Manifest digest:

sha256:4bf7078001fe582fae5abdedee1dfece8c33d88db0393bcdaee937f1df3fedbc

Size

60.16 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:577618155ef7608c22106cd4c6c2d73a5c1c1e9eff58e838f7ac866b71993079
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:a218ff733c505f1197ff258d8dcbfaee878988c34bc265a611bf52d069360026
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/helm@sha256:8590652736361a3aeabc30c86cfac4b7588a904b1b33e681a9a91685ca08a345
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:cb974b3c80eedf7cc7f136bf8d17feeb179045aeef5f118a54ab62cdbd484e46
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/helm@sha256:106f879c3c5ab8707a21830a29e46649c2a273004795ddb771310bc071f2f633
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:777b219426a9d56e1787b57e060b0a79b89b6b2f4f4deddb83d408c2bd4bbdd6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:544dd8f121d3a12d5788e99be70cbf4d547b785503f57543ef8ffda9655ced94
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:2752d1ab36fc64824912a5608f260d76aa4fc750b37b762b992a710ce5f1fab9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:eea0cae823a21cf49895594c29d37fdbd50940c58250757a7fa05bd0f2326156
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:2c7a197b1a3ac23d26413ea4a576ed49c60100341a19f26801fc983c3861dff6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:208a2c48f1c10ad13e4af4f26e78f99754ba054bc826106e2bef67c1eafe408c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:d01bd58a726231a12b81e7b7c6f78203d581404de1835d8d1ce6c54fc51d7c74
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:0c9303838444a7781f0bd32dcb61ac1356609c0b2af8dd8f5a2e0d811515ee96
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:ebb8e3946a8febf517797303d109cd084b1f1c48470436c7945547603892b958
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:6772c55661dc4e69553d0b8cec4e101a319a9db8a57b181fd7c517a0fc544ada
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:c7d89f94514f11dba8dd4da261652f38d03871de9655c5eda345271eae5c925a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:c177c244f65b2b8059835b58989482256d72707e881ce7cfad5975ee5903348b