Sign inSign up
Helm

dhi.io/helm

Helm 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.3-debian-dev, 4.3-debian13-dev, 4.3-dev, 4.3.0-debian-dev, 4.3.0-debian13-dev, 4.3.0-dev

Index digest:

sha256:63d12f689711904cf749722950d8262fb48c34c04287daa7688d09dda13b7946

Manifest digest:

sha256:a2d70be78cfaabfda98323988c06387e3282bc9595b074713670632053110aa2

Size

62.47 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:e4b734f213dd155bc33702cab52f43cb0d03ff5e84eb676b9b7f18094940cc76
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:ea0666124d5b67efe2c9ff3826937961c1f8190522ae4a67aa4129b8a9badb26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:5e0b27eb1f5d81c0b457247e6dae3f7f8aa8b4894f5ef4ba34d14080a48286a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:10e1b0315ddf1108bb96fc79654a63295f27bb464d731801d6b04b06f82dc1b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:25ae2020b487dc389eb29d9311b798358547e1b34fa03eb82b85eb74f8d46cdd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:c1663c24d24fbda4ea1471062ef64bc6baac287d352310342a23842d6277225d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:10a2cca1067a1cf22aa41845d8167e7b4acdaa72e138bf721b9572b49b7fa2b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:e15992ab2da7248252bac3a978b9974edb7f4f6253393415eb546ac97de48f67
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:bffa4db79c1eaf22df564f564d5a34f867a1622438265759516099a2601764bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:f01d356fe9c228d184a1182ecfa3cabe3fa729d6af65fe2e581942e659f8e394
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:8e7374fdf5db04caa9571fb3216fc45ab8d9222a41ef18847fc9502da0e0a1d4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:7e672154168cd2910a25c3895f09ce84b6460e0179cdb38ed6db542ec6c10fc0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:52ee9d7d01cf497cd3190d2d2018426108e42b9dc5f0196fdd50891edaa59c0b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:1ad3b6060dd6217e4e5b5d48115088ed8dff8b732b50e9032db69fdda608e233
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:871c62e7ad34314e5ab2d83dc65b5d34728698d74eeb278bbf72abb132e78a1e