Sign inSign up
Helm

dhi.io/helm

Helm 4.x (dev)

CIS
linux/arm64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.3-debian-dev, 4.3-debian13-dev, 4.3-dev, 4.3.0-debian-dev, 4.3.0-debian13-dev, 4.3.0-dev

Index digest:

sha256:d091dafbd4a50aa1bee8bd9941a7a7af5d44cffda4e145bba31ece15a37625f8

Manifest digest:

sha256:051e46bf8453fc075a629a5066a2a56710d6ee70fba1686375e5f893a891a2ec

Size

58.41 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:879f8a14fc3cba39d95248f0464ab038604d551dfac3944bb281a2fcb79c565c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:4b35c6452189a3720f48bf760c00d73b686d8c8d60cfef55ec6acdc282dae346
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:87d1481fbef1c2adf8c10126c4622a24fca6cb416c9c9deab7d333ed00475bec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:612df3dcd807f1e7496c03c5c796d7f6572e8a2c5dd325c170a679eb2dbba283
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:daff7ee0382ebadf522f7f364330715c188af1a00f76508cda3269c6416badc4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:bea34fed374795f2ada8cf8b5ad9476d64cdf4b4d0988f66a88e630a801c754a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:0e308daab983ac1b1740d0619134ae3b81a78a24936da2d0d77d9d102d5729cf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:a25c510e7df5be1068e0615bb596402c8fcc987e6e7b6b85a04c8501245e7089
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:2cad5025fd428dc1e5ec21a46a46dc7e2b2a48374eee4f233f5fc70269c10ce7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:5f4defa0e49755c0eb0d253cde6c28dcd02be0b75061384851b3b21f97fbcfa3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:e2e820a8760e2f5e22f8eee4f1414eed63488e71c22d8797177b5ae97e8c233e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:aaabfcde7ef1c53cede915dd68203281652e27ab915e376dfa3dcd79ee498491
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:b3bcfab66fa2663f7018b210913eef09a64e2c83dc75dbc838c16842a9cb755e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:116fab47c942600f28a85a045985ece5eb39749abcf367bc7940269a3870093f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:cd97ba0cd8b7e626edb3bc637f7a8a4789c425e8026363b9521c66efff0e704d