Sign inSign up
LocalStack

dhi.io/localstack

LocalStack 4.14.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4-python3.13, 4-python3.13-debian, 4-python3.13-debian13, 4.14, 4.14-debian, 4.14-debian13, 4.14-python3.13, 4.14-python3.13-debian, 4.14-python3.13-debian13, 4.14.0, 4.14.0-debian, 4.14.0-debian13, 4.14.0-python3.13, 4.14.0-python3.13-debian, 4.14.0-python3.13-debian13

Index digest:

sha256:272565aff28b0af01a1c5061e4897520cab5d97f04b6c9a5910f9cb51da1196b

Manifest digest:

sha256:91acb57fc47ca27f442ba40cdc6d00bb1cd24610927257d78268ecdbba983680

Size

125.74 MB

Last pushed

19 hours ago

Vulnerabilities

0
3
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/localstack:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/localstack:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/localstack@sha256:59484c17e13236aeaafcc6904ace76ae4c086a1af8dc55e8aabf071baee46074
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/localstack@sha256:8ff7903e0440c38820b0c067ecda0a6b7d8b9106251f85bfbee84a98ae4c87f1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/localstack@sha256:a7257fc99e978e125aaf7fcc777ad18544e007c36754c155861a8d3ef007827c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/localstack@sha256:37e932131a3493592c1f3b431be15e6e39c850a9c290cdf54b63aef413982a50
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/localstack@sha256:35977f7fd9c1cbac68c12335be99f99bf29caccfe7991c92bd019de320fe79d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/localstack@sha256:6527a73ef0cf7ccf075e601f44799705ead12fd77ff60e83aa90dbf20d6ee443
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/localstack@sha256:dd489f0ce315c5fc0cce22eea4bfc824f030d46c9b5885fb2dc8c9e90d857089
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/localstack@sha256:c45a428a5a67fe0c034f1b480bede19c3cdfdbf17be120a8bd74879ed19498ec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/localstack@sha256:493c6e314a4e9ff89ce363d27b1d98eaf1289b455ff8c933548e3cf86c142d1b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/localstack@sha256:a1584541d1706bdd4e399104cf40b10239ff028d676d355fc2ae371f3e2b811d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/localstack@sha256:07f6f6d6988c8ad30b94d355a1efbb7b8c67a8a92b32a4f54b1f19f946499acb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/localstack@sha256:63f157fa9caf6dfc0ad41300fd6319201843323ae0c9d9162575f08c4ebdf0aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/localstack@sha256:efab96f67dfa027ff3135a2e8dc84e4d709d57d368b6e216476772735606f57e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/localstack@sha256:b017275be8dcdb0516ff607029783dc7ccd7f692d3797864d08b747dce07557c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/localstack@sha256:6032d69ba7243f3be92105f506bf9ff8d0a7bf6695b21d0ec3638305b40fe879