Sign inSign up
Kured

dhi.io/kured

Kured 1.23.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.23-debian-fips-dev, 1.23-debian13-fips-dev, 1.23-fips-dev, 1.23.0-debian-fips-dev, 1.23.0-debian13-fips-dev, 1.23.0-fips-dev

Index digest:

sha256:9aabfb3dd6ab627adb8856cebe215059da9828e6972d63d32e34cdf58374d847

Manifest digest:

sha256:ab1bd0e4dfea30e360464465d1c9f89ba7756955438729f1a4b1ecd8e2e73600

Size

35.25 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kured:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kured:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kured@sha256:2d412290f172d6cbcbcc2315a26863027c33384ce3e795db2fe8375742183266
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kured@sha256:fd838058e53c14c545537775a70fe1292d75f49d9b265c4614441fa4a736f32a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kured@sha256:c3825e0ce244e2cad8d833c278ea9f81ffa482223864d65d228525b206fa0b48
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kured@sha256:ef251e305feb90e7d1c5b7fa9828f1644cc98cfe69f840c704f06fe5e604a1c8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kured@sha256:5053a3dfe3ae2f5a804b2acd72507b2ee75581cb36c408df9425810065cd6fbe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kured@sha256:4356c1688d4d449165123ada8d0658b4bddf0cd8d1f584d97b017406800e0c9d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kured@sha256:1984357232b7a58d3d38865a835e7ca0e2cc65d70efd5e6982f7c82b377b600f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kured@sha256:b1bb48a49511e49ffbd3100ada0cc838ebf5936b9fb5875767468ed59f03a7e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kured@sha256:0264f57cbac800d94a8f3d2fbe39e7f54803b13db85a48cee67559c99571c3a9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kured@sha256:ec0fe5652ce38fd2e177b72eb5128a92d28134ae3ad5c57c56f5874c801b15bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kured@sha256:3e2b6808c456457b672d0135a2c34dea4320b533bea2ed9b17d2ab50d6d14ad6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kured@sha256:ea02f46157661f47beb5fc23da0524147a376649e4d64589043479129592c96c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kured@sha256:5d1984d81ee5d5797ab9937ff84e6e16852125c16b553c501d0115814a0bdf91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kured@sha256:0d29c3e29da6b6b6a0d8d27e81d02710142d6c64a39535188243f8388e771a73
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kured@sha256:b60b6777dfd628ddfb5cf607c08f2d5068cb250296d9b5dfda92b38a20d20355
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kured@sha256:182c605b0e220511fffc6d6d3418bca0869b23c00ef9513fde45ac1ee4ff8bd6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kured@sha256:751e7d16c208c8ea8a7ccf9407c7db1cc9851a2c873513572f3287ffc766d865