Sign inSign up
KEDA

dhi.io/keda

KEDA 2.19.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.19-debian-dev, 2.19-debian13-dev, 2.19-dev, 2.19.0-debian-dev, 2.19.0-debian13-dev, 2.19.0-dev

Index digest:

sha256:e8621f0298faa284e413ab2f9b6d6d5b3eba563a0bafcc9ae7d677fe2b441ff6

Manifest digest:

sha256:cc1caedb0f2bdd9486357aef58edcef4cd29032d7b3998a1d8906a8b2a86bf12

Size

101.76 MB

Last pushed

3 days ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keda:2.19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keda:2.19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keda@sha256:8c6e0fa31dc7e4fcaaeca1ef1e79e8c0cfe2c4eec8a9214a7333f556bc79f915
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keda@sha256:9b52beb31b9594213eb616593c946390186c92763443976d7f5167a1dcb063d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keda@sha256:a635cb438742bcffca934724b583b4015671df2e981b9face3ca008b73c838f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keda@sha256:1bc90ec70f59c2c529e528f6d4a2f177ec2e9fe690a85680d20a91f24c7ecabb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keda@sha256:c38c9a9dbef4fd6deec112d03aa3054097d756122a1c4e0ac0a87419677da77c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keda@sha256:09b18d6e1664a35c2e4f878c729942ab1f5fd81008868f7ffafecd1240efa802
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keda@sha256:de7681337a8b4a16ec37cac5c292bd586729e74af62351bf05da7ce72d1f7b2e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keda@sha256:ee2807e8b262edb7ae6b8b1fafc09bb7eaf848c4211dd35cc0475d47e555d759
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keda@sha256:1155733548102f6dceff414125de52424de84ed4ec680dc85ce4901dda0d94ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keda@sha256:0976368ef1c163206698d0a1376dd5afb93d1970fc2cf83b13328c4e859cefee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keda@sha256:d13a199e0aecdec9adfaa2391a9aa6e82f9a2a977b0c34806b1a3c0b1e8c7191
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keda@sha256:b9d142a4a31cd680fd2f4a100087740f579de3baa0ba3f16d096eb751f23c9ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keda@sha256:66b31749bc8a6701b04b3531d48c004ea3a78d81600d3456e3ab9e32c567a4e7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keda@sha256:1590d9404ce25ea1779b63ed910cac344f7f2e8cdff99e7c98e911a8e0fcf373
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keda@sha256:38a3bf6d5d38bdbd51f71f8da07d498f1c77880a8b0a9000993949384d318f97