Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.22-alpine-fips-dev, 1.22-alpine3.24-fips-dev, 1.22.1-alpine-fips-dev, 1.22.1-alpine3.24-fips-dev

Index digest:

sha256:5ce2e9c0cd90748e936ecf4e57948d136f25e1c2e61883b9c91c692288a869b2

Manifest digest:

sha256:751a1d0d2a595fb6fa0b6eedb2a7c15d3438ccd17703fe5fd235e3a17b35b177

Size

34.20 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1.22-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1.22-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:784dd3e800580f1db0ecf67caa5f111c235732a627f8b054e03b735522235964
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:a33d946137a24b7a6ba02c8c0c945f39f51b79ff7e63ed788bacead28ac4b596
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:bc9fd9a8c1806852d34c6adbf150d967d819e4182f6eba61fc31c1af34ec11c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:102b38419c45c6bfff82095b6a91bc24731b9eaef2a6aab0115ecb90aabfb07f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:6c7489d1700d324df80dab8ca60be163ec6dba5cc2e19d9b4e73dbe6da9c3297
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:2d4d05edcd9f6528d883863a0e7d92651621287e9d629f5384c89cbaf30e4d25
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:4c132cc1685df0663218a777b8be13e6dea375c609cae836f0b5ea0098dc7634
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:128ca8332088fe1f2fe656b38cf317aaff4746d4af3b660a446650e14ebfe9ca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:4c0acf71c942b88669ef292f48012614f8b43b13fdb705af773bda9fb8c0e9e2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:397ada074404ebb0a5e77cb4288261f5d259a8b4438d1b9a8b605d70be360b6c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:ac68a497ac28bc3726e61708925e1d05b1d1753e04e136980b1040496cffcf69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:d0578849429d618aa13a5332ccfc6107f072d4989370df11dc21206321e87b1a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:fc83129bb82aa3d2175d6a29d4731ee1660e52001630abd91abd5ce146350a47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:9a55e7407ad9c44d5098fd16f84247621aec090f08d19f628d39437816f1e042
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:908182bee274a2f5d8209a090114fff38f5ecc5b8544d2623d70f7be3582c3b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:2433b80aa9e32c5acff6b406f1613ffbf001140088309091828f629cda59ef11