Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.22.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.22-debian-fips, 1.22-debian13-fips, 1.22-fips, 1.22.1-debian-fips, 1.22.1-debian13-fips, 1.22.1-fips

Index digest:

sha256:f09f7c9c729bc948523634363108b30144b4e0dcfa399dc84801ba6d95210c45

Manifest digest:

sha256:b1ef519b5eaa1c62a188760c4d1e7bd70fb26c162be1cf7c83e812744f99bc20

Size

23.02 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1.22-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1.22-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:a77d03653193ade90f89e60c68896147c45a493dfd7f19fd2e456b90b114c299
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:f80c91d3f6a9971ce99ad7f251fcb5c2ce450e310751f2738b436fe39d9038d8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:4a92ccc12a51b31b12c664535f4f103f79e35bb9a7ae924980f3894c07865db7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:1b28ca153e08fab436c5172d4245b9671514c45be1b8031b074ff77118ae255d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:ff265283003b24d55bf561856926488f55e3455a7b3e6c563f58728b4c70dd37
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:7b6788f5de6b6adbe54178f9e718cad4dfc10fa10c6f6dde547fbd385c6f84a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/knative-webhook@sha256:3c7b74f0cfa800e3b3f5df6c74360c9d3117d753ed5da124ae18bd807132818f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:1dfa1c29d7e8833f97d3ce52317f20e5ee78270646c5a9f78d14b881b0cd5973
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:66809c5c26bcb376b7b2c8a653fb757ce753def2017c5c4bdfc92e5614ba0e3a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:72583c3695e851c5a34ce50b7314413b0e1645b3382c4225b5f026b6759a75a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:f8d7134c3a932998e9be27cab3be2a62ad71d5c7165d35930520d4f1bacefdfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:2d3691eacea4dd8e6923921440417bc418a813f00431d434331d9298072bd597
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:e24c775218009d9e5751901ffd7b49c6332e13339e72d3bb86f93655137713ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:82d24cbf124f07b25e818550bf35339bf006771caefdd914abf117105c3e1c98
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:19f72be54a5471d9b495f66e7f5cf327d4faa3931f020e1641747762d4b69244
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:f1226dfd02101abda098d32becd12d0e0ee4b1b115cf7e2c9ef4625f5f750b21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:eb701002505ce1efa227ae46cf28dd6c6c260d5ebddf00a0ee53ca508f0391df