Sign inSign up
Helm

dhi.io/helm

Helm 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.3-debian-dev, 4.3-debian13-dev, 4.3-dev, 4.3.0-debian-dev, 4.3.0-debian13-dev, 4.3.0-dev

Index digest:

sha256:d091dafbd4a50aa1bee8bd9941a7a7af5d44cffda4e145bba31ece15a37625f8

Manifest digest:

sha256:c0c6e08fa6f5b7fbc08ae3cc8436f79a884586ab30a520009fa7b5abc7f6aed0

Size

62.47 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:86b603a6cf4d4b8480dc24ee30136c35d04c43c6e330b3694e7229a70820f652
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:b8897af2b9aee4734b2f4ab4cdef8675203878d0e0a318dc73a53530a3488e6f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:57b3e8af88e71b589b6357137a10712e4663c69a691bfa6f20a393724adfb59b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:ad5d4bb60b206d0ded4a23f9b269a41a746e57e12fe2453e3f644b57dd2f9645
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:7cbb86193bf1783269bdcdb668c7e9f605598492d04cec1bc3111e1690c67e30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:5002de6b99dbd534315b098eed7da09547bf47c6804a0a9cc621080ac221ba6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:f09e02e876ef05650a12bfcf9cc35dbe19ef3a8f7f385ba657c62d11426a3652
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:39898386d519c56cf049053d862e7a961db271bb9a0235d4392e2785184d0b86
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:8b4e848c436ad709c761e90d3b66a0b69f6b662262343974ced28306f315e90d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:2ff98bc5f03d0db9bedd9fee7db09a53f8ff892f100548ad013330b8f1330690
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:660b6685fd9bc0bd0ed6b9ae5766a48388b07d6c4273025de4d9894f6102f6ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:e3275363659def457963694dfe6cd7cf205655fa9e961b8d4940cbc539e0b651
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:08a7d419361f0411cc6320e87235656db0787ffac1b4b22c3fd17b50aa32d0e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:c246a75f1a6aa7a44c281e2511cfa842589dd9b895ba619569c3bb53eeef9477
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:a10ae36e2b356cbf2cd3754caebb1e50dc7568ba5dfc459b8327aa312a3d1a1a