Sign inSign up
KEDA

dhi.io/keda

KEDA 2.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.20-debian-fips-dev, 2.20-debian13-fips-dev, 2.20-fips-dev, 2.20.2-debian-fips-dev, 2.20.2-debian13-fips-dev, 2.20.2-fips-dev

Index digest:

sha256:32ba8b87a445a358e42744d2b18cc3e14c09906ebe388c3a2e7c5e9ca44b3266

Manifest digest:

sha256:1aaeee5e4114d640c15c8b536dcef8a747bbde3b479d51bc6cbfac8dcb901852

Size

103.02 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keda:2.20-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keda:2.20-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keda@sha256:25a0e670baaa19888e8c4f27e649d241d23e7d02c2375a982527bdf86429c1bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keda@sha256:181028c443052b1f979d07258a5a7178728a897ce6cf06c52f2ae4b1e9e6f510
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/keda@sha256:6535ce758aa1c192718f1c982dcfb0c68fd767d7d6ad31b0ebf0a1bc4fb4ab14
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keda@sha256:317da1e12201473e97a2e5239e4de3ac6abf5ef8f1fd2deb13d3d6c2028e9e91
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/keda@sha256:53122e25a108bbc23265fc6551138c9d7121170e346274d5d4bc5f70e15a760c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keda@sha256:1072dba92c91b09aa85a4b098e63a1544c97feeab46a1ed2b344119c2d34656a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keda@sha256:1a46987736ce7a8cdca36ed3017e25e9c2ec35bf11a31583e01158728a77385e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keda@sha256:1e7d82c0b083ddf06971240db1040d9bd3c8b8491d63fc2cbe941b18ad4bba91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keda@sha256:f872ee0833f4386ff8ad1522c4f4f583d4ddd9bfdbec14062f71481459d5effa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keda@sha256:0b6baaa52eaf78dfe78d9a3e2876c5cc08dce27b09a799a85b07a226ce7566df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keda@sha256:1edf297015a449de8e9a963bef0cccb8ae7af30d5c387ce25f02dca6ff4b8aea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keda@sha256:70a56f35938ff56e269d609e2146631f99a673ee5e890015a45b8862e17fbc49
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keda@sha256:5519d04387cab4f7a0f44f892864cf7d907153c3afe0d191c6ecb2e4175c4473
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keda@sha256:96f1b9aabf7fc4bc12631b6c714549cdb328114cb40b807117759070e522e979
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keda@sha256:c24fe54488fbbf81b3d68d5be1f7bf64d46da5255a38a68db50d27c113956897
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keda@sha256:79c9e839c834e71a6e7aa4b82c8c68332db0cbd7c3f0366a69306f94c21e0445
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keda@sha256:21e479a9aebd6c8c0db5a2aa5104b88da56d54d95ba3a119d5441068b8596b4c