Sign inSign up
Helm

dhi.io/helm

Helm 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.3-debian-fips-dev, 4.3-debian13-fips-dev, 4.3-fips-dev, 4.3.0-debian-fips-dev, 4.3.0-debian13-fips-dev, 4.3.0-fips-dev

Index digest:

sha256:05c64a357c5230c90f597cd494ad07e1a5da227f5686273bd9c7cb8c7faf2d57

Manifest digest:

sha256:a359e0f6a30b4f65152b4c94dae78bda7a1e287b53fc58659ffc9a25c6ea4a8b

Size

63.20 MB

Last pushed

10 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:5845a396b11209f37d227ff3fba010b1ece9a0aa7f36a3ce0c2ab22d687e5c70
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:908ed208adc877b9c83a3c99c252a3f8c821ea7e5580e51345bf672ccde521c6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/helm@sha256:d8a5f7a27a1a61805e6d21ee51b5279bc81f46776a4edf1b6ba108b1f03ffb53
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:74ba14b2bacfcdf37f2abe830116d0ea1c5bd4452a7a98eee771ac1291be3964
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/helm@sha256:e51f1a092fe3bbb3ba67a013c2c0f92001c6c822551a4768aa6c2453075db7f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:64ac472d5a403b4771def0e16e00730d4a087ec3af92038aba68d84339cd3b62
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:4715221a4974789fbeefd6c65395d0d0c4a13d4f84dc1c10f90cedd784f57dc9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:a136dea6bd3d2fa7fa6413aaba42e166717a8b08b80bebfd5225ebeddba2bf64
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:f6ca19647c4a6a7943157439932241e3181ac8b625b9d1ef9baaa57176271838
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:10a4ef648ab78331b63118fbc90830bfda54d6323b55fd218011ae55fd8f43fa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:8c9c2920b39c6ab289536a29cbdf8e7bcdea079c9a45d81bf43c24fc70e2a0a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:ef8ebdd8111f86ce5794c0888d3f58167f5a7f07e36cdd4f6c2e684365a73f69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:9a3f2e62ca960b005cd6fd457c52a3e14818d1f4f282dc57a576ffdb7085347f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:976b09051509cc2aeda4e917c40de592969d2513254d21e2315f2fa341df2d87
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:e12ac74e9c71d3aee59380ab3bcadb9b5ef2c84e2d6c96cde087509a6b09796f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:5056f1be472bdf853637c83d90cf2c5e2224bdd3f2c8f851b4d2929d63800a02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:4bc7ae13dd86f20988062c6b6dc28fa7b2534f4e3d30196ba87deabd286c6655