dhi.io/knative-activator
1.22-debian-dev, 1.22-debian13-dev, 1.22-dev, 1.22.1-debian-dev, 1.22.1-debian13-dev, 1.22.1-dev
sha256:35b2a96f105236bb2690d2774b54bf83e440c4ec5f8656edb2464a136083b3fe
Manifest digest:sha256:fd353298808f809607cb4e4a6ac040b5304c16a46f5ccb9e55867e08cd9745a7
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/knative-activator:1.22-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/knative-activator:1.22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/knative-activator@sha256:bcd3865fde28f4f38ae3e28222304cccb385f22d094425b741d07384fb538ac5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/knative-activator@sha256:895722574dbcc9c88176908bbda87685898d688ca35f198d6ba9f56c3abba4bf |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/knative-activator@sha256:351dd1d1617012f642711fb1f807691e1e798d424c1457b1e6ee86fd47d3b76f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/knative-activator@sha256:107a7c3de8f41e722ba917718c2975556b912865f995654ae468fe347c054d9c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/knative-activator@sha256:c22ea99748df2e9a71ab85c7eb4f220f201f76ddc758d8e0f12853791bc991b0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/knative-activator@sha256:12d876b2a854da1ba453b3a8b1d252b325ab45e42d82ac84ff583de0fa459606 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/knative-activator@sha256:e78ee8563dc1c2c9c9ef3afc97659a66c19c939f0aeb03921328dfd12d30d4b5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/knative-activator@sha256:4408cf0c081b5fe4d842c252421efedf8b7bfe132f507acc5f2568fb66065deb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/knative-activator@sha256:21dbd37edc92d220cbba1c32c4d78d48126e2aceada2c49edf47b996056298af |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/knative-activator@sha256:515c92c9a16fe18576f3b36909dab7239ec662b3c125d80f7752e1d6d8d12fc4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/knative-activator@sha256:b7415668a38d28a47cd676c46a25d6e86f7bed63d897c16a81f0298c782c9f8f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/knative-activator@sha256:6a73ca2f7649df6faac74de12567732d29ad628a11ba015e090bfbc3d3613dea |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/knative-activator@sha256:ecc858edbbb6c8c2fc50bdd5e9e3fa23666f9bb1dc6be2b4e06138fd166e63ba |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/knative-activator@sha256:a18de0ff5cc7b4c81b4707c44eb8974cb7dd76409a24d6e5492679a8b54b98ac |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/knative-activator@sha256:081b7a98e20ef9824db0617eb6a91dace152d5483afe2e65b1805c05d26bb498 |