Sign inSign up
k8s-sidecar

dhi.io/k8s-sidecar

k8s-sidecar 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine-dev, 2-alpine3.23-dev, 2.14-alpine-dev, 2.14-alpine3.23-dev, 2.14.1-alpine-dev, 2.14.1-alpine3.23-dev

Index digest:

sha256:eed30fe2496483779b1eed19b4bdbce5f3aaff4b33a9b1f3392a2437171ce157

Manifest digest:

sha256:3509f55890c896c93d4b001f63ef59ca3ca8b0ca5576676c90d5a88a8453f1f1

Size

28.81 MB

Last pushed

1 day ago

Vulnerabilities

0
2
3
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8s-sidecar:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8s-sidecar:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8s-sidecar@sha256:56ca988371eb5a65366e61a96d65f923d9167e1dd12ff796b7fe9b5d8a94453d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8s-sidecar@sha256:fa57b2b9dbd344efdb2687e0206668f70c289a6561bb8dca6067b67aad27090f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8s-sidecar@sha256:75a841a94a114496ccf2e362ff5870d02a7396b239016a94349a170673d162f3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8s-sidecar@sha256:3625e10ddf1a5d1114908887f93e275853ae6c478e12166f6f5ce5fb29f29f0b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8s-sidecar@sha256:1aaac2749611a6e82e564ae333f14a622bd1720c76e3b1c21bc3434a92016f37
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8s-sidecar@sha256:b8544806b3957d3b3b6e040eecb05cc5dfb4e9d882b1f1ba625dac2837fb9478
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8s-sidecar@sha256:7e8e869227c13a9a007a0aeb287ff3feea85ea6952aa93f670befab2af168130
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8s-sidecar@sha256:dc7b8fa92af5a843ec2e63cf79e6c2412344aeb379727c37041d4cbacd241c38
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8s-sidecar@sha256:2a43c78f1dd754606d63b6683dd62a03db1c811ff5645015724bae0c6ac67432
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8s-sidecar@sha256:e7b9acd4afdfb59d183eef8d390f21d14f0acf168c07505f97a93286fc11c629
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8s-sidecar@sha256:2958a953fe07f7cb5b9c00e517b5084c483209e2afeca7ba80adda09fbafea78
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8s-sidecar@sha256:834a5da1cb4fc3e9fa72065b1f5e935dc8019d75958916b9b1d6dd5c35c8df2e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8s-sidecar@sha256:6f7c8bafd43f6dfad2d9a65b747d17c19e6dd40a07c134773a95767013f68686
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8s-sidecar@sha256:c7230d7e54d84d4fd18a60aafc106f1cef1bd2b6e4fa0bceabda73d59d3a8ebe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8s-sidecar@sha256:3ba432b6f16323dda4e351ab719a390545425d9bba36bb25c8c523aec7b8dec1