Sign inSign up
K8ssandra Operator

dhi.io/k8ssandra-operator

k8ssandra-operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.2-debian-fips, 1.30.2-debian13-fips, 1.30.2-fips

Index digest:

sha256:69d54a07007d07223442617c1cb3a6a4555ce3ac97685549a4426a3e3f40d498

Manifest digest:

sha256:88f059cc42fb1f4a4cce3d3c8386fa22b8e8932f9559a8f2673ec9c06bd5cdfd

Size

21.99 MB

Last pushed

21 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8ssandra-operator:1.30-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8ssandra-operator:1.30-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8ssandra-operator@sha256:7d9704e9e7ec172714d4e01e2b28fef757161cda62e27db2376cd0e2615deea6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8ssandra-operator@sha256:622bb426eb28a3fe70f1999346becd44b96eac67c4e1cbf15888fdfa36effc12
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8ssandra-operator@sha256:f57a10e1ec64593ceba7bd7609af4ac1668c1b85e48eedd6aa02ef5f5c60a410
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8ssandra-operator@sha256:b074f8e6523267c76c6ccfdab96ce2d58e67b909f0cf94eb30b978b4eb01112b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8ssandra-operator@sha256:aa3f44817adcefc56a0b0a551b3f6c319bed2d6ff0d1e5fcf1b7847b7c928325
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8ssandra-operator@sha256:535a4a240ab888e574299eb1ececc07b3320d30dcc89dbd9f65e81afe17fb16a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8ssandra-operator@sha256:b229acd687d0507627f00151f7987721838ee363786175f44fff3183362aa67f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8ssandra-operator@sha256:08e60f6921c46fdf6e4c734b2a6db485a9d5d8e2ed85225d1054f54456773421
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8ssandra-operator@sha256:f25af9ce0be86466b79b6b81c7d0e525adbfd0c5b945db977f581a2b289dd002
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8ssandra-operator@sha256:00d7f1e2e17b08a7e4fe6b7112dac018b3d1a680250134c358484ec3f1f316b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8ssandra-operator@sha256:93fc3e10667b3fea69874ed4ef7ec86ea28d9ac315f4ff2ddd3f950b23554fe4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8ssandra-operator@sha256:801c6451a117cf7a11766aa08c0d6215fabb1e6d10e0a674af684a0c12e1eb82
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8ssandra-operator@sha256:9e8e457c76b43ac24a9bbb84f1fb675091e7965b898eb12406f546e45d5adb4b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8ssandra-operator@sha256:eaf12e934200e861bb698cadab4c45f6a398c7dedb9a08933eb1196011931cfd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8ssandra-operator@sha256:46c504e2b1a80718bdf773c0f1b501c4d8575f3370f457443805665296343ba6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8ssandra-operator@sha256:2389f76a62440ada16a094f0ba85bccafe6dea9414f5c876743fef81381b2669
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8ssandra-operator@sha256:ad04ab6a3f1176b6a7fa1bf95a4d8cc8e3dd97f4ba4f9e0ed707610b1d70bde9