Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.22.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.22-alpine-fips, 1.22-alpine3.24-fips, 1.22.1-alpine-fips, 1.22.1-alpine3.24-fips

Index digest:

sha256:bebaed7c5c3bba8bd4a5ce2bb82557dab3c48a83a111bccc7318bae59c507e39

Manifest digest:

sha256:92859c84429085cb5c17d6bb2188ff1babf9f38b00c1297ee5be3ad81c339d0e

Size

17.87 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1.22-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1.22-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:929d9d490ab1dfe29a664dae267289f02a4a0cb84f014fc3c922dea1f85a0b00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:9fe791cc2627cc4eb79b025e17634e15b0956628d3a6e441024fff0138d656e4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:777e214f2ed27856708a63ec71ed5ba8b8b8ace51b236eb39c14247ac7af9743
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:8233bf316a03a2855fd016ead9a3cef0511a0cc065e899b16225f5b45c463489
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:0a6b26ebd94703f1731b073db10b7c23b4cd94f4c9bb7b2c0950f577480869ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:9c8b2d356090e663e2a5c0473e346e28ddd2c68a1029e1fc22209941dcca5327
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:35a1bc0b32081bf20e817eb13994359e63c40f69f66fad26215a2ba026a080aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:af3862f0840cd45bdbd150b8a22c3a300c6ebd8a1dfa674f151f728e5971e4cb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:51aa6d9c4745cf02c08c72e1de10d9ff73ff276b975d1091593188931a349450
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:738d3bcf852fa018c74b7599587ac056858f6b05217c93cfec695fee2956e1db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:1f14d3aa33fadf8064c0a906416ae68f73d017378f9d9c4ccb0a55e68856411e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:9c73886039f4ee2e2d7f8fc6c0b5b9a0199644159ae9e646f179239f2ee5ec40
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:3af4614957da7f4d133774312ceb1fa9ab250091666cf6c955723acd2b892cf2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:fb019425966c6adb53571650500f8a65e0097c19bf23496f5823786f6f1b888c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:b4aa155bc382372566deaa46b94058941ccc20ef0366768d3859d2f9423d97dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:bd63a5503d4e467a69877d915e3423c018f797d4c8fca5f6979c09d4af983394