Sign inSign up
NetBox

dhi.io/netbox

NetBox 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.7-debian-dev, 4.7-debian13-dev, 4.7-dev, 4.7.2-debian-dev, 4.7.2-debian13-dev, 4.7.2-dev

Index digest:

sha256:2fd8c5c45068d8a6dbde8daaf672cd52cbfc825bea673267bdfbc6fc59c34fe2

Manifest digest:

sha256:673884a104f5406af7ac5cac895eaac150b4b419b673c9578f9398826cd6d689

Size

129.60 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netbox:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netbox:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netbox@sha256:a92991eb9eafc051add563b483a1b1ad56be6ca75fe1b357c080a35b8e8dff85
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netbox@sha256:5a1757734b78db4a3f9bd0dcbfc51d9a2ec11396d177433fef32025db5a01f21
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netbox@sha256:69bd21b65ebc5dc42f93f9e8d7f77b8878da7df490ee57b4865e09f366e6b3ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netbox@sha256:8599263bfea810c5d42af8e57c8dc262ffea9d4d9b784b49dc12bbe9fe21b078
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netbox@sha256:0e62b34dbf35aa598d4dd2c37bc666bc7b159edb70e9320bcfb6c00702f209e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netbox@sha256:19d4dde17fb6a28638002aa9967a605558ef353a7c7556b89ef23882dce31059
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netbox@sha256:9d528ac58fb9651d9efa0cc754708aebde27e0fed55a022cc7ae6eaa45304917
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netbox@sha256:282b92a1b7d7fe151191a27e1c1cc839aa59755fe3666ca12fd03437e7b9d35d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netbox@sha256:13e581f9b3e284b62b4680c717bc7924976238118fa8d28ac36b55bd4262e4e8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netbox@sha256:b2ca404501723d8374da58fd8942f209429f77c377813e967de7fec51f6e2e90
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netbox@sha256:771bb1e51b68cc463a75f09536221d4a9b96c2f1094e8891c374b048a08dc502
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netbox@sha256:da811a8be7090341a9e10244687dc65d57e5065aa2cd35932de9fefa0fdf730f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netbox@sha256:ea7f64e7d10868a67bd0f16fb14105d4743ede88d6e056548dc4c799c4165af4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netbox@sha256:14dd1537756977c462c1c22d264cd2382cb210e6bb05f0ec64b73c03925e83a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netbox@sha256:3d64e99ac09dc9f4d166da8f0d9b842094309c6e8349cacdda68996f71fae7d5