Sign inSign up
Kustomize

dhi.io/kustomize

Kustomize 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.1-debian-fips-dev, 5.8.1-debian13-fips-dev, 5.8.1-fips-dev

Index digest:

sha256:d3ddb30b96468dafbe21cc2124d277fb7772376baaaf0fc59ee0fa45f2891a8b

Manifest digest:

sha256:5f72bfafbd8f45a681d9017488243bf0451bae3e7a809ade173ac9b1aac2710d

Size

50.31 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
3
12
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kustomize:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kustomize:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kustomize@sha256:5791e7c6bcdf5e3cedf17bed8552183df74bbda3699781b669df6e7a83913229
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kustomize@sha256:1112594f2cd823b75f2bc2c9762be4d15beba8334620f092a417b84f2284683e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kustomize@sha256:3daf1ba355d6cb34d467bf5a4c85c1552b5a12ccf2f60eed4afbe7ae9411aad7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kustomize@sha256:661f032eb37ebf44e06de76518b4ecc25d479353694989d0ddeba4298cc64ce9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kustomize@sha256:1fecd8e792fbb6056df0115a1bcfd127ac40c751a59aed08e498599bf7fb09c5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kustomize@sha256:9f1bedbec622d7fbe6c535ffcda9f1dd221a46f2a2927294c9aa65d3fef349d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kustomize@sha256:7dfa86739f5f70ea0dbeb45f9d5f25076067ff48c7ebc7968c6e374f719f0cbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kustomize@sha256:0c3ed84dc04bcb58a3a15abc607c607aac59538b6d5a3c8bade53b754169513f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kustomize@sha256:87b185348f2c5b22ea51b7a19ad80eb8ac9c31e6917f50c275bbef718ebbfaa2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kustomize@sha256:b755cbdacc913c8455c2cbc3e0c80d820ac3c3dd0b8d1e55558f057f0322c4f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kustomize@sha256:7cfd94db464ff1998848592c911a95814cbd0926cec7420ebebcb921efe4c6f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kustomize@sha256:3b805c2d505dcfe66598ffbf5a76c1f0e7ea26fbcd10488c2a622c719fea8783
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kustomize@sha256:22609ead37a96f722a2d41d6c82d65447ec463ce120b770609bcbd55ce48d77d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kustomize@sha256:512fed7fe6ee4df5504cb0ce2baf16a821fc76eb468e92ae214f6f48409ea721
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kustomize@sha256:1c5e5ba44b20786f443e75a9b1ee252f3c749ba7674707e022f6499fa203bd36
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kustomize@sha256:a341cae9e1b75fa51bc1242c8339e379d710bcca6fbc5b753dcf26e92db2f5f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kustomize@sha256:77652a2e0867328cedd62695a478cf678986341773e4bac0d8370233cf94ec97