Sign inSign up
K8ssandra Operator

dhi.io/k8ssandra-operator

k8ssandra-operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.2-debian-fips, 1.30.2-debian13-fips, 1.30.2-fips

Index digest:

sha256:6e6417d9dc44d05804374fc6496ce59679d7cdd30912081427d07fddb6c3c5e9

Manifest digest:

sha256:ff9970bd75febe86ad5099a1df48e81a98a554e163312d341c367d117da8942e

Size

22.00 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8ssandra-operator:1.30-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8ssandra-operator:1.30-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8ssandra-operator@sha256:1a664a5c6d390a4f257ddc34819d8e6a7e267fe224f8ceb4926c7d8ea0f85a35
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8ssandra-operator@sha256:fe36d806e221a866ee9e88748de28d489441ca6ee6fa120539d600ce523ef486
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8ssandra-operator@sha256:41994fd92740ea51e7c180153e29fc6da9c8fadaecc3ece0c40f904fca426097
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8ssandra-operator@sha256:6ae5e33381f7a52e0a62d3df40e703dd931dc31eaab572d134509505586617a0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8ssandra-operator@sha256:84d689d9778aac673460d51d00c7e5b7cf0da652c8606bdf0a108d9ce2cc9cc0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8ssandra-operator@sha256:46e046d1668d8e6cae623103e9e0eb511b65b97dfb127d6c5adb4baf959db1db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8ssandra-operator@sha256:e444f8201632d2173f610710dee39dfaca44b61c7e597bbbacd682ea0d654650
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8ssandra-operator@sha256:e32d09a7685c1ad49ce9c88a7cf6de1576de3c52a2551fd9d101edf5488e235e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8ssandra-operator@sha256:1e66289a7b3332a8349c05074e97f624d498b2d9e29db089ddcc01d6c7ac97fd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8ssandra-operator@sha256:9db75ecbb66e5df78bb20eebd4d4ad28a4e5adf77b9ab733e70e12ca30d7c1b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8ssandra-operator@sha256:eb86b450c38abad4682ecf9aff3850d3971f8fda739e057d1a8cbf6c700dc9db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8ssandra-operator@sha256:47e0bb7045d205aa862e4a04e38d3f61ffc63aad07b85891eb9a90d4d78ea7e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8ssandra-operator@sha256:89edba879a0d1c629d3e03649a3251e2b29c9e3bde1affb2dc9ae60dee5b5ae4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8ssandra-operator@sha256:16c9bd61f1769fd3712a3f19e9373cd5359cb4d969d350bb0f6de8426c4ac2fc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8ssandra-operator@sha256:f11ec43954b42d54b3c138d1d0d2ec916c8b91d406432d6619d2e8395e4e45e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8ssandra-operator@sha256:0d7650e0b12233877bfd2c63256b903c8408bc7f099efc943d992b9b4726c680
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8ssandra-operator@sha256:36b5bfdd97e25e4fd5cf9c380a115a7580c3d3ab909fa30a36f87f4d37ee6426