dhi.io/k8ssandra-operator
1.32-debian-fips-dev, 1.32-debian13-fips-dev, 1.32-fips-dev, 1.32.6-debian-fips-dev, 1.32.6-debian13-fips-dev, 1.32.6-fips-dev
sha256:f5dcd8c6add1f12bf8f769d1c435b84b27c7d20fc989a6829ec9274e46a2c1c8
Manifest digest:sha256:bb5a39748e75265f312ac7db99759721b449fa6c339a0e228a368c8cf1d48316
Size
50.61 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/k8ssandra-operator:1.32-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/k8ssandra-operator:1.32-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/k8ssandra-operator@sha256:38f9ef3652cefcf9225f024a230f6bcf3a0d4f792001fa2870ce897f14ff8666 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/k8ssandra-operator@sha256:0c12e2db865d1b994757ee43f62db58cba1811fc6aaa2cacc73801b3d1e3d422 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/k8ssandra-operator@sha256:4830fb8272faebe5c8c3f5d9eb7cd48cece84451f64dbb4a1aeebd2387919364 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/k8ssandra-operator@sha256:6b66cbd62d5936a6cd8f6220415f57aeb7634b151344c31b89cbc952c7bdfd34 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/k8ssandra-operator@sha256:3384aac5891b6ebdb0ba8d44dfd9a412183d3bb9a30111212a03929e9be8afd8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/k8ssandra-operator@sha256:0aaa426e6abf6b06aff4e9f7db72e21d68c7caec318935bc8131d6479612675d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/k8ssandra-operator@sha256:3f7a487cc2a2895aaafdcf2673a321f5cb49c42abdb7834afd7d8d730c7db214 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/k8ssandra-operator@sha256:7e830b978115de954ad3e71864fd172b57e4d27d6cd2ee1482a972d33b6da0f1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/k8ssandra-operator@sha256:50dc89f118b477b9d67a8a20d97e57047cd9b4bed9f2719adae1ecd801af602c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/k8ssandra-operator@sha256:5a934863442b07efb2301eb5bfd9b9d294fa014f20bcebb49eab8811a06db710 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/k8ssandra-operator@sha256:29bbc79c32ef22717890bdcb0fd1aa28b4353f9d5a0bcfcf7e2cd6cd24a45fcb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/k8ssandra-operator@sha256:4092bb328f8c6af94fca936da7a3ae3e1487183bcb01ce4548673fc1f8210d0b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/k8ssandra-operator@sha256:5b05629c9024a837b8d2dab2f532a00b5a0d2b51b0712b994a8dff20b373bef8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/k8ssandra-operator@sha256:66601208c58dfd59a10c395f86b3978801b93cb9b1006ea0dba1c2c06819613b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/k8ssandra-operator@sha256:78997bd8e973c87f20d7d08cf9f7735e75ecb9d4f0dfabefe4520f03c0af306a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/k8ssandra-operator@sha256:bcf99b2c5b506b770c90d42bee97795bf4a64ebd493bcae64f4cc7225a4e77cb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/k8ssandra-operator@sha256:ddb7017d2c347d9faa9fc491a941734506dc27d5c7d88090db59b53e832169e7 |