Sign inSign up
Helm

dhi.io/helm

Helm 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.3-debian-dev, 4.3-debian13-dev, 4.3-dev, 4.3.0-debian-dev, 4.3.0-debian13-dev, 4.3.0-dev

Index digest:

sha256:d24b9af2ca138f705010d54a8790a940120a5c2df4e893a11cca6e5dc9ef42b7

Manifest digest:

sha256:805660978e66abf1014ae39c18eaa0b5d06adb24410dd318f0969058e0ef834d

Size

62.48 MB

Last pushed

2 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:df2f6feed469970bdad3c62e42d4bfbde69844bb6e9900cb4984b2ff0489c81b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:6e7139623dd5172d71e6e1665d4c118d478191bde190c4f8a98c0381ca3401fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:d4e88638cc05a06f59adb46aa298176a6213e6f0abc9df26b5dbf40463efde80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:80dd9094d82c9fb853b22b8defae3e397de28c7c9c2b4b19f32e3441b8d57589
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:a9aa3089abc840a2da80feae5eb349066c247c3ee4061c90128eda0d03504c50
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:0415e505a55d3959a17056d0fd91aff2942025c0dbce7b27a8709a301b034cd5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:c54ed53b3491fddd3de0e300a123c6a490f20d9effacd62013bd767367191e08
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:e29f32053455894fe2a0c52bc9cbb98caead15b2a4f1547188d9df4d9cb57c1c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:9dc71c8c848dd85427540d2ef882fd383b3c03e10e517b2beb683adc4ca38eaf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:838ceb1eaff9296d09077734ba009fb2f21ac057b13bea7e8e26c91319718caf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:1b97358c0f4feb22f284384ea4e4e351599dfa1d0030dc71f358b0111f31d3fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:9d00d76802aa307839e548b53992637b14b7009e92cfbb64fa213edcf0b428c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:3485658e7fc9bc2554cbb1dd68013cc24ff01c6f08d09a54f315e51553de5ce4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:0ed357301af1f145da65a7058c05e5d35421ead87e14407d984f4c4798ad0486
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:bb8689cb70e6e4c22019ddf7f363a1b46d3c210c749f9b669638eb7a633e0c92