Sign inSign up
Kustomize

dhi.io/kustomize

Kustomize 5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.8, 5.8-debian, 5.8-debian13, 5.8.2, 5.8.2-debian, 5.8.2-debian13

Index digest:

sha256:7ada2756d9d8b5945e51461c2179cb0bd27944c51f406cfca95fda56788526cb

Manifest digest:

sha256:07a65a6c7592612c7b54da377a29c3ee5490491a4e396ccb300eef875e491c8b

Size

37.26 MB

Last pushed

8 hours ago

Vulnerabilities

4
12
0
1
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kustomize:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kustomize:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kustomize@sha256:7d7bec4dd48feaeb08b450a10479592e9ce9c71b750e47dc1ca6ba9862dae0be
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kustomize@sha256:2df605f8194798d14dba5f9ec42fe797f4eec4ad4c22950ed8cc96a966cc2832
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kustomize@sha256:2debc12b45572f950c5b8b2e93879de60fe3a14154b203b392f2ca7bf41c7272
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kustomize@sha256:31d8020e0efdf9332aa8daeaef01aac859726508fcefbb6f249ef94ed95e2e00
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kustomize@sha256:8f7e6373a58d7be3689655330d52411e60af85446e05c4c29b4751a3dc527d77
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kustomize@sha256:c46d073b577fdb4dcdfb611b867eebbd901e30a4f8381c0279596febba0f0170
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kustomize@sha256:72ffe39c4971e6c9150c53b7132ff09f1a11739e5e1ebaddc8f352b1b4c2aecc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kustomize@sha256:353cc941c1784e7b6e5accf2dd4f65d71177fbfbf36922e939047e8752863efa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kustomize@sha256:5fe19d664cb7c258aff3ada7ba2cc84fb2464f5d6e8e497629d6b54d1c53c6c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kustomize@sha256:bdaa6bdf95eabdfc80298d83a5b1074f5d5fef7a0dede4628ad955e7989c3350
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kustomize@sha256:7d6b8d33bacccbeb8e350294647b40adca594696fb1054d39ec2aee9376b68e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kustomize@sha256:3ff60c329d6bee67499296bfae6a949671788825a6ebde2c9bd6d74b27a138be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kustomize@sha256:9953d3929fa520f4a05942689e8c2d40c0c83d3994278651de1dadfea93379cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kustomize@sha256:acdd5cd0ae8ad8bc0ca0b4a6b6ddf768520d8856efb521f70eb72c178294a744
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kustomize@sha256:666fc4785f6d225e6442f8a503f6854d4ca5f82bd53ad6492add316f9ad023ae