Sign inSign up
LocalStack

dhi.io/localstack

LocalStack 4.14.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4-python3.13, 4-python3.13-debian, 4-python3.13-debian13, 4.14, 4.14-debian, 4.14-debian13, 4.14-python3.13, 4.14-python3.13-debian, 4.14-python3.13-debian13, 4.14.0, 4.14.0-debian, 4.14.0-debian13, 4.14.0-python3.13, 4.14.0-python3.13-debian, 4.14.0-python3.13-debian13

Index digest:

sha256:49d3334eb95513201e8a98dc2d6ec653ab546a10ed14d4888ff66e6db4822e17

Manifest digest:

sha256:1d5903a2d276f2cc96acde033081f0ecc94de0982525d2bb8edca7b8ff41807e

Size

125.72 MB

Last pushed

8 hours ago

Vulnerabilities

0
4
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/localstack:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/localstack:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/localstack@sha256:06e20897abfb253c63c39007b008d70b7c2fdbbfe475d84986c4e6e87aecb086
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/localstack@sha256:5d36ffb15b25885b09ab5a179acfb1ad32330488618f6519f9c970b3b188ae7f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/localstack@sha256:b518548590e50e3f9f2c76bc512381a712411de82de36f9406a8d4a68ca610ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/localstack@sha256:fa395f2a6dfeed4965a0a0ee61777a7105ef6d7dcabfc7fedd193dbe773c3aff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/localstack@sha256:128aa47f857cb2c1edd419fa929f9bbec5cce7715c7edf0d829633681355623a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/localstack@sha256:b596f0fc727287fc83afd693a5ec8d48e81cd1dc0b68fbeda43fbd9f167c6c32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/localstack@sha256:f96614e93390958e1c2bbef934a7764a53cc4e02deeab5eed296401f74ce4bc4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/localstack@sha256:b2308efa78fb58c3f6e42a899f1fa1448161dac04fbd7266f5350dee59b1be61
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/localstack@sha256:42398b7ed4c4145005a2198d94d8639d6172b92ebed15de412bad859fe32790a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/localstack@sha256:ebf626addd9b84600d241dba170313a7c64f4df93447dd8317f31d15a0cfd1a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/localstack@sha256:9a0b7d96de51129423c571da68d07ed5a4aebea09983a20535517a6aa8eac878
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/localstack@sha256:ea5f2235cb3aed4296f55603852c6711529f46fe51beabe0cf336b5b920ac05b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/localstack@sha256:b7f5a3493f24eae8acd76e2b65e2b68faa6079bb27c7b96b5f2d1e5fbc0c8cef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/localstack@sha256:7b256e6e4365839e29568352aea8dd0fa9b01bb4c7a74a346e4d6d25701ab875
SPDX SBOMhttps://spdx.dev/Documentdhi.io/localstack@sha256:dabfdbdeab6a9b623c032985b5f9dfa0d31ef274fc4cf547a658ac884aaa06ac