dhi.io/kustomize
5, 5-debian, 5-debian13, 5.8, 5.8-debian, 5.8-debian13, 5.8.2, 5.8.2-debian, 5.8.2-debian13
sha256:f8e7e0ef65a82744577ad2b8515438ca8762f43425906edde4d26409ab1f51cf
Manifest digest:sha256:eba8f5778b4611ca67009b5f7d4cc6280ebbd6822615148bf0a4cb0c0e41ce08
Size
37.26 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/kustomize:52. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/kustomize:5 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/kustomize@sha256:235520c7b5e86dc567357570bc0ce827865e3357759e8527253352c82fc841ba |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/kustomize@sha256:3310dda10e860ed52d3485dfa18aa03cc1b48fb3d43dfeddbc6ac75ae0df185d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/kustomize@sha256:76e67ab52ca37b8dfe064a16138926334b12c5fb6be09ec6338a18294cb2ab12 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/kustomize@sha256:3752a3dd3202c046aadf68134f397996c1159881f110911ba5e6681a7d378972 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/kustomize@sha256:21f221f829479ee19d23f1be5d8bd1599ece9789cce00d4a8afec7109f65e9de |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/kustomize@sha256:79ed25a8b194e9445a17550cd7a4354b0e5733172cee0686ec51bc35477716fa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/kustomize@sha256:79df51a8ddbb79f0aca4c5435a08aea3cc45d5cd088ec034a48af9c4204b3bbe |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/kustomize@sha256:73fe1ed06569c48b8f94d7128dbcf342e3f398d458f5f95f79e9d61f0b41e337 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/kustomize@sha256:a0bda508cc19aae504703fd9050509ace9df0d5fd0ff4c195bc8146ce0cef4e0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/kustomize@sha256:1cf9c4fcc04a67890fec1e8a95146039e986fb2d74ffb54f2e0b0825b242378a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/kustomize@sha256:5a1a33d4657ac7e8aac43a271d4d12111420e80c3321d13741c28831242144a7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/kustomize@sha256:428cd7bb00ae1ec315ba9123372688f06fb308b734bd40e187e2661fd3d8e69e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/kustomize@sha256:310edff4daae4157b7fc6527a8059dcb8cc981f628309953abbf21942b2d2620 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/kustomize@sha256:1f08cec9b927880c2ea1cdaa2615ab77689efcbc399a639ca7aeb35eed330ce6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/kustomize@sha256:0bf30a6272021ec6e2506948c67da0b726bda47a8b657535f249c269f0a496db |