dhi.io/keda
2.19-debian-fips-dev, 2.19-debian13-fips-dev, 2.19-fips-dev, 2.19.0-debian-fips-dev, 2.19.0-debian13-fips-dev, 2.19.0-fips-dev
sha256:d85f28ac906017337d3a5777fddb0b0e53b75ef1987c74cc5940ea5f8f2350d8
Manifest digest:sha256:eae5eb46f954c0902ad72ad0413441024adb4eb744407a9f7b23c54c15f87f9e
Size
102.57 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/keda:2.19-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/keda:2.19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/keda@sha256:f2ad169077c10e5f92ee9637b3b51c36b5ea03f5063996e38850515dd2335439 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/keda@sha256:3908348999c1b00527471af73449e82961fc477a39feadef4b0556e5c203cb5f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/keda@sha256:1c552e190c52d9bbd2a377ff9d9de89e081f0dc4da0c9a48cf191a257e8ca3e4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/keda@sha256:d9facc82cfc073139a85b2fee08357eb5c7977cf04121d5c6957ba100fe7aa8f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/keda@sha256:6c9425ee70697282eae03649782ec47f840c18d6c506467a3173607f03e37bc1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/keda@sha256:4886ae2fa1f5c2817aefa566c026a74b6da3886e047db8da67e99de50805277f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/keda@sha256:45d1cd95290f7eb5b87c1e5b761f897657115f6f3dd6a6ceb362b2da42c7753c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/keda@sha256:88f5c9e65100adb3abff41e1ebfd73d3b1b89274cb6036fa154c4a5e1e0116da |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/keda@sha256:7fd18557c363cc880f59240640959a92c513cba84e002b5abd2a747bc6ed3f1c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/keda@sha256:aa4de73668c22c26e1236b477f42b2ab1cd40aa7ded41197c898b28d0378f848 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/keda@sha256:41b3fba527e53d2f110ac8e9a57e579a55cd5207e46f74a968f32a7e418e61d6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/keda@sha256:6780bbc34672ff2e9cddc09c6e7b4075b45caec48756cfea892b45dfc9870a2f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/keda@sha256:f201975f48e61ef0c46c515f78ace5874532e4f6e7b973a2ee3fd7046696bfec |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/keda@sha256:fc9363eb6e0d138820a29512015c0fc98302fe8de338b5cb26688a17a478141a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/keda@sha256:e96837c870ac1686b1b7b7246765e0a61e6bfcb774d6835cd0ac7188cd1d9f59 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/keda@sha256:74c9d7999890643122aed9c9704126eee78ea819b6e54cfc94776dd3aa902e9a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/keda@sha256:674266401661b4cc2d8e2b8e982efd1a55c317784da835e4f255977a62d81c5a |