Sign inSign up
K8s Device Plugin

dhi.io/k8s-device-plugin

K8s Device Plugin 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.20-debian-fips, 0.20-debian13-fips, 0.20-fips, 0.20.1-debian-fips, 0.20.1-debian13-fips, 0.20.1-fips

Index digest:

sha256:2937e062629b9e6df23a47fa639ff8b66ff4629c2bd1f0d0d4ee6ee13f587dcd

Manifest digest:

sha256:417bae9fed23cdcb4e3da8e0c81952285d8484a6fcf47f4eba28ca42b3e83390

Size

44.45 MB

Last pushed

16 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8s-device-plugin:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8s-device-plugin:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8s-device-plugin@sha256:4c08b4d3452c6f1583fd2c6a28763f2edbfc2671f38734658247ecd9149419c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8s-device-plugin@sha256:6b328be718fafdd782553583eaa7e90619b31375785a7f43e4e896cbc6868f19
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8s-device-plugin@sha256:1690ea463d44b413f76f5e78d24e5b5e84cf32de667c1e1bcb7dbc50c5eff971
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8s-device-plugin@sha256:391305ef34ff9a4c005c31205271bd7c59cb8601ed3f63a9c56ef5291d23e931
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8s-device-plugin@sha256:f6b4185a4d85cf455cd8d29f81ca2df990dc67e602f7dec49a48ac86a8ee2672
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8s-device-plugin@sha256:066925a0b1bfc8f7dd48724c3d75a641d3e6827279b0b8eb2ac0c99a19f4a796
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8s-device-plugin@sha256:b7682977d4869b23382a174f42ac955ab7d4bacd25646f24755e557e3482e0b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8s-device-plugin@sha256:7db60dd91869bfad50692b92cf66917ba440293f8aa4072d35d5bc30573db7bd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8s-device-plugin@sha256:a534b5c2c4c931cf681aaaa7c694d6a1c4bbefc5f258c126a3f7c84483f360c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8s-device-plugin@sha256:487184f224e9f0f8222569fc152e45194a75da3e4b690328d4863554c87c4918
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8s-device-plugin@sha256:ad0a291cdd032f0cc52f637ed4add9d14707b211c000d8c0d15dec3dd58ccd4e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8s-device-plugin@sha256:5edeb9de975b3ab316aef67310f224ee8b162bf0a474ad2bfc0ffe96279563bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8s-device-plugin@sha256:309b378b32b42934ed2b1c0cb21df5d8406991d6bd750024265afea04eeb3e39
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8s-device-plugin@sha256:b27a99827f5e5bd8c2ec2eb3ed870028a21b42e4c980f8c3067df5b151f9d325
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8s-device-plugin@sha256:c3be7c892e0f14a92e679e2b44563d5df548f1cf25a0639e5bbc43e5d74ebe28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8s-device-plugin@sha256:a879a5b81c1e2cdd6bd703f324c29e1174fb72886762526341401ab699a45aed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8s-device-plugin@sha256:f5de195f56f200beaecf7b8ba912fc9a2fde589222cd38dfbf16f50b07d91af8