Sign inSign up
Kured

dhi.io/kured

Kured 1.23.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.23-debian-dev, 1.23-debian13-dev, 1.23-dev, 1.23.0-debian-dev, 1.23.0-debian13-dev, 1.23.0-dev

Index digest:

sha256:86bafd2d423cb1755c9a760de8adcd3f390d4bd2ae3aaa723e164e8651846e39

Manifest digest:

sha256:0e13417d813bc4f18a50ed7a3f7466cbdaa917dc7aea2f4ba0c7bde92314d698

Size

34.44 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kured:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kured:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kured@sha256:0c6ec1986bd1cd3b79c76c334f3a83f8b055ec9212047254e99ec780da876bac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kured@sha256:3a2115740ebf1b4e142636900263afb5cebf1e80326cf411cec04f5c5445e6a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kured@sha256:ea9bcd52575cee98e83a03eec1571d15f56605be786af78a16bf34bb4b4d0496
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kured@sha256:30d947f16916609b5dc49f41112384468545f384fc926a889da8abf81aa010d0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kured@sha256:8319ba2307d36c11a0a6a1a6137d408d6a1a5f93152018d3fbc8b6d3d7d8d4cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kured@sha256:646db630adaad7b8af90b2d9f4695240b4dd4ed2fe81accbbab392b7d8388cb3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kured@sha256:eb3c58279c7feea49b69140fe0c588ee3c2aca2843cf712262d2d6a68958a61f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kured@sha256:fe9b0124de2f78451c8b52bb0b8949047fe18161983a79b524763c7cc5e8043a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kured@sha256:fbef136529190cf049ba8cd28056ff7a44eb1224dd17451fb2b5008ec910a210
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kured@sha256:7ffab936764e22c5b3c0b29d65c7a8e537404e10b08964d1db9984bdc142bd6b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kured@sha256:ddc502255c21e966a14989bd8488897ce16d037975f170abddd868f8c55126d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kured@sha256:56020da7be51542f97916258aaae73481b7b2410f29864d681230a1f5e6f9668
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kured@sha256:d6096fa5aa27bf1513969d8b7dfb8c5df4686d2753ec1aad9812bb07784c8dcd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kured@sha256:ee0d2b35ba3e6b7345207b2a192ec20ff08ca09ad326f551d4e7056a452b1a56
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kured@sha256:2044793cd5c8c9442dc291cae497a2a3b37a15d2732d6a71844e60bb72b578af